CVE-2019-8993Missing Authentication for Critical Function in Software INC Tibco Activematrix BPM

Severity
9.8CRITICALNVD
EPSS
0.7%
top 27.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 24

Description

The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid contains a vulnerability that could theoretically allow an unauthen

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-gjvf-862f-699c: The administrative web server component of TIBCO Software Inc2022-05-24
CVEList
TIBCO Active Matrix Service Grid Administrator Unauthenticated Download of Sensitive File2019-04-24
CVE-2019-8993 — CRITICAL severity | cvebase