CVE-2019-11208
TIBCO API Exchange Processes OAuth Incorrectly
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint, when the implementation uses multiple scopes. This issue affects: TIBCO Software Inc.'s TIBCO API Exchange Gateway version 2.3.1 and prior versions, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric version 2.3.1 and prior versions.
El componente de autorización de TIBCO Software Inc. TIBCO API Exchange Gateway y TIBCO API Exchange Gateway Distribución para TIBCO Silver Fabric contiene una vulnerabilidad que teóricamente procesa la autorización de OAuth incorrectamente, lo que lleva a una posible escalada de privilegios para el punto final específico del cliente, cuando la implementación utiliza múltiples ámbitos. Este problema afecta a: TIBCO Software Inc., TIBCO API Exchange Gateway versión 2.3.1 y versiones anteriores, y TIBCO API Exchange Gateway Distribución para TIBCO Silver Fabric versión 2.3.1 y versiones anteriores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-12 CVE Reserved
- 2019-08-08 CVE Published
- 2023-07-08 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Api Exchange Gateway Search vendor "Tibco" for product "Api Exchange Gateway" | <= 2.3.1 Search vendor "Tibco" for product "Api Exchange Gateway" and version " <= 2.3.1" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Api Exchange Gateway Search vendor "Tibco" for product "Api Exchange Gateway" | <= 2.3.1 Search vendor "Tibco" for product "Api Exchange Gateway" and version " <= 2.3.1" | silver_fabric |
Affected
|