CVE-2018-12411

EUVD-2018-4385
The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: 3.3.0; 3.4.0; 3.5.0, TIBCO ActiveSpaces - Developer Edition: 3.0.0; 3.1.0; 3.3.0; 3.4.0; 3.5.0, and TIBCO ActiveSpaces - Enterprise Edition: 3.0.0; 3.1.0; 3.2.0; 3.3.0; 3.4.0; 3.5.0.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
tibcoCNA
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
tibcoactivespaces
3.0.0
tibcoactivespaces
3.0.0
tibcoactivespaces
3.1.0
tibcoactivespaces
3.1.0
tibcoactivespaces
3.2.0
tibcoactivespaces
3.3.0
tibcoactivespaces
3.3.0
tibcoactivespaces
3.3.0
tibcoactivespaces
3.4.0
tibcoactivespaces
3.4.0
tibcoactivespaces
3.4.0
tibcoactivespaces
3.5.0
tibcoactivespaces
3.5.0
tibcoactivespaces
3.5.0
𝑥
= Vulnerable software versions