CVE-2018-5428

HIGH

TIBCO Data Virtualization <7.0.6 - Command Injection

Title source: llm
STIX 2.1

Description

The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data Virtualization: 7.0.5; 7.0.6.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104518

Scores

CVSS v3 8.8
EPSS 0.0049
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (2)
tibco/data_virtualization 7.0.5
tibco/data_virtualization 7.0.6
Published Jun 20, 2018
Tracked Since Feb 18, 2026