CVE-2024-10218XML External Entity (XXE) Injection in Software INC Tibco Hawk

Severity
9.2CRITICALNVD
EPSS
0.1%
top 77.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:N/SA:H

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-gcg5-h35m-25rv: XSS Attack in mar2024-11-12
CVEList
TIBCO Hawk Stored-XEE Vulnerability2024-11-12
CVE-2024-10218 — XML External Entity (XXE) Injection | cvebase