CVE-2019-11208
Last modified
CVE-2019-11208 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint, when the implementation uses multiple scopes. This issue affects: TIBCO Software Inc.'s TIBCO API Exchange Gateway version 2.3.1 and prior versions, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric version 2.3.1 and prior versions.. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint, when the implementation uses multiple scopes. This issue affects: TIBCO Software Inc.'s TIBCO API Exchange Gateway version 2.3.1 and prior versions, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric version 2.3.1 and prior versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tibco | Api Exchange Gateway | <= 2.3.1 |
References
- http://www.tibco.com/services/support/advisoriesVendor Advisory
- https://www.tibco.com/support/advisories/2019/08/tibco-security-advisory-august-7-2019-tibco-api-exchangeIssue Tracking, Vendor Advisory
- http://www.tibco.com/services/support/advisoriesVendor Advisory
- https://www.tibco.com/support/advisories/2019/08/tibco-security-advisory-august-7-2019-tibco-api-exchangeIssue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11208?
How severe is CVE-2019-11208?
How do I fix CVE-2019-11208?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11202An issue was discovered that affects the following versions …
- CVE-2019-11203The workspace client, openspace client, app development clie…6.1
- CVE-2019-11204The web interface component of TIBCO Software Inc.'s TIBCO S…8.8
- CVE-2019-11205The web server component of TIBCO Software Inc.'s TIBCO Spot…8.8
- CVE-2019-11206The Spotfire library component of TIBCO Software Inc.'s TIBC…5.3
- CVE-2019-11207The web server component of TIBCO Software Inc.'s TIBCO LogL…8.8
- CVE-2019-11209The realm configuration component of TIBCO Software Inc.'s T…8.8
- CVE-2019-1121A remote code execution vulnerability exists in the way that…
- CVE-2019-11210The server component of TIBCO Software Inc.'s TIBCO Enterpri…10
- CVE-2019-11211The server component of TIBCO Software Inc.'s TIBCO Enterpri…9.9
- CVE-2019-11212The MDM server component of TIBCO Software Inc's TIBCO MDM c…5.4
- CVE-2019-11213In Pulse Secure Pulse Desktop Client and Network Connect, an…
Are you affected by CVE-2019-11208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
