// For flags

CVE-2019-11211

TIBCO Enterprise Runtime for R Server Running On Linux With Containerized TERR Service Vulnerable To Remote Code Execution

Severity Score

9.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.

TIBCO Enterprise Runtime para R - Server Edition, y TIBCO Spotfire Analytics Platform para AWS Marketplace del componente servidor de TIBCO Software Inc., contiene una vulnerabilidad que teóricamente permite a un usuario autenticado activar la ejecución de código remota en determinadas circunstancias. Cuando el componente afectado es ejecutado con el servicio TERR en contenedores sobre Linux, en teoría, el host puede ser engañado para ejecutar código malicioso. Este problema afecta a: TIBCO Enterprise Runtime para R - Server Edition versión 1.2.0 y posteriores, y TIBCO Spotfire Analytics Platform para AWS Marketplace versiones 10.4.0; 10.5.0.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-04-12 CVE Reserved
  • 2019-09-18 CVE Published
  • 2023-10-28 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tibco
Search vendor "Tibco"
Enterprise Runtime For R
Search vendor "Tibco" for product "Enterprise Runtime For R"
<= 1.2.0
Search vendor "Tibco" for product "Enterprise Runtime For R" and version " <= 1.2.0"
server
Affected
Tibco
Search vendor "Tibco"
Spotfire Analytics Platform For Aws
Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws"
10.4.0
Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "10.4.0"
-
Affected
Tibco
Search vendor "Tibco"
Spotfire Analytics Platform For Aws
Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws"
10.5.0
Search vendor "Tibco" for product "Spotfire Analytics Platform For Aws" and version "10.5.0"
-
Affected