Cross-site request forgery in TIBCO products - CVE-2019-11203
Published: September 20, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin in the Workspace client, Openspace client, App development client and REST API components. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Affected software
TIBCO Silver Fabric Enabler for ActiveMatrix BPM
TIBCO ActiveMatrix BPM
How to mitigate CVE-2019-11203
TIBCO Silver Fabric Enabler for ActiveMatrix BPM - update to 1.4.2
TIBCO ActiveMatrix BPM - update to 4.3.0