漏洞信息详情
TIBCO Software API Exchange Gateway和TIBCO Software API Exchange Gateway Distribution for TIBCO Silver Fabric 授权问题漏洞
漏洞简介
TIBCO Software API Exchange Gateway和TIBCO Software API Exchange Gateway Distribution for TIBCO Silver Fabric都是美国TIBCO Software公司的产品。TIBCO Software API Exchange Gateway是一套事件驱动的Web服务平台。该平台主要提供高速接收、路由和转发请求,在请求者和服务端点之间路由请求等功能。TIBCO Software API Exchange Gateway Distribution for TIBCO Silver Fabric是一款用于TIBCO Silver Fabric的API交换网关。
TIBCO API Exchange Gateway 2.3.1及之前版本和TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric 2.3.1及之前版本中的授权模块存在授权问题漏洞。攻击者可利用该漏洞提升权限。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.tibco.com/support/advisories/2019/08/tibco-security-advisory-august-7-2019-tibco-api-exchange
参考网址
来源:www.tibco.com
链接:https://www.tibco.com/support/advisories/2019/08/tibco-security-advisory-august-7-2019-tibco-api-exchange
来源:www.tibco.com
链接:http://www.tibco.com/services/support/advisories
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-11208
受影响实体
暂无
补丁
- TIBCO API Exchange Gateway和TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric授权模块安全漏洞的修复措施<!--2019-8-8-->
还没有评论,来说两句吧...