CVE-2018-12414

HIGH

TIBCO Rendezvous <= 8.4.5 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), and Rendezvous Daemon Manager (rvdm) components of TIBCO Software Inc.'s TIBCO Rendezvous, TIBCO Rendezvous Developer Edition, TIBCO Rendezvous for z/Linux, TIBCO Rendezvous for z/OS, TIBCO Rendezvous Network Server, TIBCO Substation ES contain vulnerabilities which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Rendezvous: versions up to and including 8.4.5, TIBCO Rendezvous Developer Edition: versions up to and including 8.4.5, TIBCO Rendezvous for z/Linux: versions up to and including 8.4.5, TIBCO Rendezvous for z/OS: versions up to and including 8.4.5, TIBCO Rendezvous Network Server: versions up to and including 1.1.2, and TIBCO Substation ES: versions up to and including 2.12.2.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105871
Vendor Advisory x_refsource_misc
http://www.tibco.com/services/support/advisories

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 31.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (5)
tibco/rendezvous < 8.4.5 (2 CPE variants)
tibco/rendezvous_for_z\/linux < 8.4.5
tibco/rendezvous_for_z\/os < 8.4.5
tibco/rendezvous_network_server < 1.1.2
tibco/substation_es < 2.12.0
Published Nov 06, 2018
Tracked Since Feb 18, 2026