TIBCO kayıtları
tibco üreticisine ait 230 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %0,9
- Silahlaştırılmış
- 2 · %0,9
- Pre-auth RCE
- 21
- Düzeltme kaydı olan
- %2,2
- Yayından KEV’e ortanca
- 1555 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')61
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-352 Cross-Site Request Forgery (CSRF)9
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-863 Incorrect Authorization7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
230 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
80Hemen | CVE-2018-18809Silahlaştırılmış | TIBCO JasperReports Library Directory Traversal Vulnerabilitytibco · jasperreports library · CWE-22 | Orta6,5 | KEV | %79,1 | 7 Mar 2019 |
80Hemen | CVE-2018-5430Silahlaştırılmış | TIBCO JasperReports Server Information Disclosure Vulnerabilitytibco · jasperreports server · CWE-22 | Yüksek8,8 | KEV | %49,0 | 17 Nis 2018 |
42Planlayın | CVE-2009-1291İstismar yok | Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Messatibco · enterprise message service · CWE-119 | Kritik10,0 | — | %6,4 | 30 Nis 2009 |
42Planlayın | CVE-2007-5658İstismar yok | Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.tibco · enterprise message service · CWE-20 | Kritik10,0 | — | %6,4 | 15 Oca 2008 |
42Planlayın | CVE-2007-5657İstismar yok | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote tibco · rtworks · CWE-20 | Kritik10,0 | — | %5,6 | 15 Oca 2008 |
42Planlayın | CVE-2007-5655İstismar yok | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote tibco · rtworks · CWE-119 | Kritik10,0 | — | %5,6 | 15 Oca 2008 |
42Planlayın | CVE-2007-5656İstismar yok | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote tibco · enterprise message service · CWE-399 | Kritik10,0 | — | %5,4 | 15 Oca 2008 |
42Planlayın | CVE-2008-1704İstismar yok | Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow tibco · enterprise message service · CWE-119 | Kritik10,0 | — | %5,4 | 11 Nis 2008 |
41Planlayın | CVE-2008-3338İstismar yok | Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1;tibco · hawk · CWE-119 | Kritik10,0 | — | %4,8 | 13 Ağu 2008 |
41Planlayın | CVE-2010-3491İstismar yok | The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Sertibco · activematrix businessworks service engine · CWE-20 | Kritik10,0 | — | %4,5 | 26 Eki 2010 |
41Planlayın | CVE-2019-11210İstismar yok | TIBCO Enterprise Runtime for R Server Exposes Remote Code Executiontibco · enterprise runtime for r | Kritik10,0 | — | %3,7 | 18 Eyl 2019 |
41Planlayın | CVE-2014-2075İstismar yok | TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requirementibco · enterprise administrator · CWE-287 | Kritik10,0 | — | %3,1 | 27 Şub 2014 |
40Planlayın | CVE-2018-12410İstismar yok | TIBCO Spotfire Statistics Services remote execution vulnerabilitiestibco · spotfire statistics services | Kritik9,8 | — | %4,0 | 10 Eki 2018 |
40Planlayın | CVE-2019-11211İstismar yok | TIBCO Enterprise Runtime for R Server Running On Linux With Containerized TERR Service Vulnerable To Remote Code Executiontibco · enterprise runtime for r | Kritik9,9 | — | %3,7 | 18 Eyl 2019 |
40Planlayın | CVE-2020-9409İstismar yok | TIBCO JasperReports Server Fails To Enforce Access Restrictionstibco · jasperreports server · CWE-276 | Kritik9,8 | — | %3,5 | 20 May 2020 |
40Planlayın | CVE-2018-5435İstismar yok | TIBCO Spotfire Product Family Remote Code Execution Vulnerabilitytibco · spotfire analyst | Kritik9,8 | — | %3,2 | 27 Haz 2018 |
40Planlayın | CVE-2018-18815İstismar yok | TIBCO JasperReports Server User Information Disclosuretibco · jasperreports server · CWE-863 | Kritik9,8 | — | %3,1 | 7 Mar 2019 |
40Planlayın | CVE-2018-18814İstismar yok | TIBCO Spotfire Authentication Vulnerabilitytibco · spotfire analytics platform for aws · CWE-287 | Kritik9,8 | — | %3,1 | 16 Oca 2019 |
40Planlayın | CVE-2019-8993İstismar yok | TIBCO Active Matrix Service Grid Administrator Unauthenticated Download of Sensitive Filetibco · activematrix bpm · CWE-306 | Kritik9,8 | — | %2,5 | 24 Nis 2019 |
40Planlayın | CVE-2020-9412İstismar yok | TIBCO Managed File Transfer Platform Server for IBM i Arbitrary Command Executiontibco · managed file transfer platform server | Kritik9,8 | — | %2,3 | 9 Haz 2020 |
40Planlayın | CVE-2017-5533İstismar yok | TIBCO JasperReports Server credentials disclosuretibco · jasperreports server | Kritik9,8 | — | %2,0 | 15 Kas 2017 |
40Planlayın | CVE-2017-3181İstismar yok | Multiple TIBCO Spotfire components are vulnerable to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied inputibco · spotfire analyst · CWE-89 | Kritik9,8 | — | %1,7 | 24 Tem 2018 |
39İzleyin | CVE-2020-9411İstismar yok | TIBCO Managed File Transfer Platform Server for IBM i Authentication Bypasstibco · managed file transfer platform server | Kritik9,8 | — | %1,4 | 9 Haz 2020 |
39İzleyin | CVE-2021-43049İstismar yok | TIBCO BusinessConnect Container Edition username and password leakagetibco · businessconnect | Kritik9,8 | — | %1,3 | 15 Şub 2022 |
39İzleyin | CVE-2021-35498İstismar yok | TIBCO EBX Insecure Login Mechanismtibco · ebx · CWE-521 | Kritik9,8 | — | %1,3 | 13 Eki 2021 |
- CVE-2018-1880980Hemen
TIBCO JasperReports Library Directory Traversal Vulnerability
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %79tibco · jasperreports library7 Mar 2019
- CVE-2018-543080Hemen
TIBCO JasperReports Server Information Disclosure Vulnerability
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49tibco · jasperreports server17 Nis 2018
- CVE-2009-129142Planlayın
Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Messa
KritikCVSS 10,0İstismar yokEPSS %6tibco · enterprise message service30 Nis 2009
- CVE-2007-565842Planlayın
Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.
KritikCVSS 10,0İstismar yokEPSS %6tibco · enterprise message service15 Oca 2008
- CVE-2007-565742Planlayın
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote
KritikCVSS 10,0İstismar yokEPSS %6tibco · rtworks15 Oca 2008
- CVE-2007-565542Planlayın
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote
KritikCVSS 10,0İstismar yokEPSS %6tibco · rtworks15 Oca 2008
- CVE-2007-565642Planlayın
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote
KritikCVSS 10,0İstismar yokEPSS %5tibco · enterprise message service15 Oca 2008
- CVE-2008-170442Planlayın
Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow
KritikCVSS 10,0İstismar yokEPSS %5tibco · enterprise message service11 Nis 2008
- CVE-2008-333841Planlayın
Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1;
KritikCVSS 10,0İstismar yokEPSS %5tibco · hawk13 Ağu 2008
- CVE-2010-349141Planlayın
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Ser
KritikCVSS 10,0İstismar yokEPSS %5tibco · activematrix businessworks service engine26 Eki 2010
- CVE-2019-1121041Planlayın
TIBCO Enterprise Runtime for R Server Exposes Remote Code Execution
KritikCVSS 10,0İstismar yokEPSS %4tibco · enterprise runtime for r18 Eyl 2019
- CVE-2014-207541Planlayın
TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requiremen
KritikCVSS 10,0İstismar yokEPSS %3tibco · enterprise administrator27 Şub 2014
- CVE-2018-1241040Planlayın
TIBCO Spotfire Statistics Services remote execution vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4tibco · spotfire statistics services10 Eki 2018
- CVE-2019-1121140Planlayın
TIBCO Enterprise Runtime for R Server Running On Linux With Containerized TERR Service Vulnerable To Remote Code Execution
KritikCVSS 9,9İstismar yokEPSS %4tibco · enterprise runtime for r18 Eyl 2019
- CVE-2020-940940Planlayın
TIBCO JasperReports Server Fails To Enforce Access Restrictions
KritikCVSS 9,8İstismar yokEPSS %4tibco · jasperreports server20 May 2020
- CVE-2018-543540Planlayın
TIBCO Spotfire Product Family Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %3tibco · spotfire analyst27 Haz 2018
- CVE-2018-1881540Planlayın
TIBCO JasperReports Server User Information Disclosure
KritikCVSS 9,8İstismar yokEPSS %3tibco · jasperreports server7 Mar 2019
- CVE-2018-1881440Planlayın
TIBCO Spotfire Authentication Vulnerability
KritikCVSS 9,8İstismar yokEPSS %3tibco · spotfire analytics platform for aws16 Oca 2019
- CVE-2019-899340Planlayın
TIBCO Active Matrix Service Grid Administrator Unauthenticated Download of Sensitive File
KritikCVSS 9,8İstismar yokEPSS %3tibco · activematrix bpm24 Nis 2019
- CVE-2020-941240Planlayın
TIBCO Managed File Transfer Platform Server for IBM i Arbitrary Command Execution
KritikCVSS 9,8İstismar yokEPSS %2tibco · managed file transfer platform server9 Haz 2020
- CVE-2017-553340Planlayın
TIBCO JasperReports Server credentials disclosure
KritikCVSS 9,8İstismar yokEPSS %2tibco · jasperreports server15 Kas 2017
- CVE-2017-318140Planlayın
Multiple TIBCO Spotfire components are vulnerable to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied inpu
KritikCVSS 9,8İstismar yokEPSS %2tibco · spotfire analyst24 Tem 2018
- CVE-2020-941139İzleyin
TIBCO Managed File Transfer Platform Server for IBM i Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %1tibco · managed file transfer platform server9 Haz 2020
- CVE-2021-4304939İzleyin
TIBCO BusinessConnect Container Edition username and password leakage
KritikCVSS 9,8İstismar yokEPSS %1tibco · businessconnect15 Şub 2022
- CVE-2021-3549839İzleyin
TIBCO EBX Insecure Login Mechanism
KritikCVSS 9,8İstismar yokEPSS %1tibco · ebx13 Eki 2021