CVE-2019-11212
MEDIUMTIBCO Master Data Management < 9.0.1 - Authenticated Cross-Site Scripting
Title source: llmDescription
The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.tibco.com/services/support/advisories
Vendor Advisory x_refsource_confirm
https://www.tibco.com/support/advisories/2019/10/tibco-security-advisory-october-8-2019-tibco-mdm
Scores
CVSS v3
6.3
EPSS
0.0024
EPSS Percentile
46.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
tibco/master_data_management
9.1.0
tibco/master_data_management
< 9.0.1
Published
Oct 09, 2019
Tracked Since
Feb 18, 2026