CVE-2017-5530
Estado: ModificadaAlta (8.1)—
The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-5530",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security@tibco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@tibco.com",
"affectedData": [
{
"vendor": "TIBCO Software Inc.",
"product": "tibbr Community",
"versions": [
{
"status": "affected",
"version": "5.2.1 and below"
},
{
"status": "affected",
"version": "6.0.0"
},
{
"status": "affected",
"version": "6.0.1"
},
{
"status": "affected",
"version": "7.0.0"
}
]
},
{
"vendor": "TIBCO Software Inc.",
"product": "tibbr Enterprise",
"versions": [
{
"status": "affected",
"version": "5.2.1 and below"
},
{
"status": "affected",
"version": "6.0.0"
},
{
"status": "affected",
"version": "6.0.1"
},
{
"status": "affected",
"version": "7.0.0"
}
]
}
]
}
],
"published": "2017-12-13T02:29:11.157",
"references": [
{
"url": "https://www.tibco.com/support/advisories/2017/12/tibco-security-advisory-december-12-2017-tibbr-2017-5530",
"tags": [
"Vendor Advisory"
],
"source": "security@tibco.com"
},
{
"url": "https://www.tibco.com/support/advisories/2017/12/tibco-security-advisory-december-12-2017-tibbr-2017-5530",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0."
},
{
"lang": "es",
"value": "Los componentes tibbr web server de tibbr Community y tibbr Enterprise contienen errores de manipulación de protocolo SAML que podrían permitir que usuarios autorizados suplanten a otros usuarios y, por lo tanto, escalen privilegios. Las versiones afectadas son tibbr Community 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0."
}
],
"lastModified": "2026-06-17T01:20:41.157",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:tibbr:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32716CA0-AC00-40B2-BBF7-898E69712A66",
"versionEndIncluding": "5.2.1"
},
{
"criteria": "cpe:2.3:a:tibco:tibbr:6.0.0:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72376148-EE12-40BD-9333-F62157FA456A"
},
{
"criteria": "cpe:2.3:a:tibco:tibbr:6.0.1:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A3693AF-9265-4F5C-8B5E-7DC1633E8193"
},
{
"criteria": "cpe:2.3:a:tibco:tibbr:7.0.0:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7E5DE4E-D81B-4EE5-AC6D-EB570ED0F1F8"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:tibbr:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "304DD405-595E-47C9-8465-724E89CA0AD6",
"versionEndIncluding": "5.2.1"
},
{
"criteria": "cpe:2.3:a:tibco:tibbr:6.0.0:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "357596C7-3A7F-4A57-846B-4B042A6BB482"
},
{
"criteria": "cpe:2.3:a:tibco:tibbr:6.0.1:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3145EF91-6E73-4BD5-9492-12ABDAFDE5CF"
},
{
"criteria": "cpe:2.3:a:tibco:tibbr:7.0.0:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89BCF16F-E353-4531-B3D4-4D5E92790E76"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@tibco.com"
}