// For flags

CVE-2019-11208

TIBCO API Exchange Processes OAuth Incorrectly

Severity Score

9.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint, when the implementation uses multiple scopes. This issue affects: TIBCO Software Inc.'s TIBCO API Exchange Gateway version 2.3.1 and prior versions, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric version 2.3.1 and prior versions.

El componente de autorización de TIBCO Software Inc. TIBCO API Exchange Gateway y TIBCO API Exchange Gateway Distribución para TIBCO Silver Fabric contiene una vulnerabilidad que teóricamente procesa la autorización de OAuth incorrectamente, lo que lleva a una posible escalada de privilegios para el punto final específico del cliente, cuando la implementación utiliza múltiples ámbitos. Este problema afecta a: TIBCO Software Inc., TIBCO API Exchange Gateway versión 2.3.1 y versiones anteriores, y TIBCO API Exchange Gateway Distribución para TIBCO Silver Fabric versión 2.3.1 y versiones anteriores.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-04-12 CVE Reserved
  • 2019-08-08 CVE Published
  • 2023-07-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tibco
Search vendor "Tibco"
Api Exchange Gateway
Search vendor "Tibco" for product "Api Exchange Gateway"
<= 2.3.1
Search vendor "Tibco" for product "Api Exchange Gateway" and version " <= 2.3.1"
-
Affected
Tibco
Search vendor "Tibco"
Api Exchange Gateway
Search vendor "Tibco" for product "Api Exchange Gateway"
<= 2.3.1
Search vendor "Tibco" for product "Api Exchange Gateway" and version " <= 2.3.1"
silver_fabric
Affected