CVE-2017-5530 – SAML protocol handling errors in tibbr
https://notcve.org/view.php?id=CVE-2017-5530
The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0. Los componentes tibbr web server de tibbr Community y tibbr Enterprise contienen errores de manipulación de protocolo SAML que podrían permitir que usuarios autorizados suplanten a otros usuarios y, por lo tanto, escalen privilegios. Las versiones afectadas son tibbr Community 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0. • https://www.tibco.com/support/advisories/2017/12/tibco-security-advisory-december-12-2017-tibbr-2017-5530 •
CVE-2017-5534 – Improper sandboxing of a third-party component in tibbr
https://notcve.org/view.php?id=CVE-2017-5534
The tibbr user profiles components of tibbr Community, and tibbr Enterprise expose a weakness in an improperly sandboxed third-party component. Affected releases are TIBCO Software Inc. tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0. Los componentes tibbr user profiles de tibbr Community y tibbr Enterprise exponen una debilidad en un componente de terceros incorrectamente analizado en un sandbox. Las versiones afectadas son TIBCO Software Inc. tibbr Community 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0. • https://www.tibco.com/support/advisories/2017/12/tibco-security-advisory-december-12-2017-tibbr-2017-5534 •
CVE-2011-1414
https://notcve.org/view.php?id=CVE-2011-1414
Cross-site scripting (XSS) vulnerability in the tibbr web server, as used in TIBCO tibbr 1.0.0 through 1.5.0 and tibbr Service 1.0.0 through 1.5.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el servidor web tibbr, tal como se utiliza en tibbr TIBCO 1.0.0 hasta la versión 1.5.0 y tibbr service 1.0.0 hasta 1.5.0. Permite a atacantes remotos inyectar codigo de script web o código HTML a través de vectores no especificados. • http://secunia.com/advisories/43765 http://securitytracker.com/id?1025220 http://www.osvdb.org/71178 http://www.securityfocus.com/bid/46891 http://www.tibco.com/multimedia/tibbr_advisory_20110315_tcm8-13474.txt http://www.tibco.com/services/support/advisories/tibbr-tibbr-service-advisory_20110315.jsp http://www.vupen.com/english/advisories/2011/0687 https://exchange.xforce.ibmcloud.com/vulnerabilities/66113 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •