« Volver al listado

CVE-2017-5530

Estado: ModificadaAlta (8.1)—

The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-5530",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@tibco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@tibco.com",
      "affectedData": [
        {
          "vendor": "TIBCO Software Inc.",
          "product": "tibbr Community",
          "versions": [
            {
              "status": "affected",
              "version": "5.2.1 and below"
            },
            {
              "status": "affected",
              "version": "6.0.0"
            },
            {
              "status": "affected",
              "version": "6.0.1"
            },
            {
              "status": "affected",
              "version": "7.0.0"
            }
          ]
        },
        {
          "vendor": "TIBCO Software Inc.",
          "product": "tibbr Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "5.2.1 and below"
            },
            {
              "status": "affected",
              "version": "6.0.0"
            },
            {
              "status": "affected",
              "version": "6.0.1"
            },
            {
              "status": "affected",
              "version": "7.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-13T02:29:11.157",
  "references": [
    {
      "url": "https://www.tibco.com/support/advisories/2017/12/tibco-security-advisory-december-12-2017-tibbr-2017-5530",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@tibco.com"
    },
    {
      "url": "https://www.tibco.com/support/advisories/2017/12/tibco-security-advisory-december-12-2017-tibbr-2017-5530",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0."
    },
    {
      "lang": "es",
      "value": "Los componentes tibbr web server de tibbr Community y tibbr Enterprise contienen errores de manipulación de protocolo SAML que podrían permitir que usuarios autorizados suplanten a otros usuarios y, por lo tanto, escalen privilegios. Las versiones afectadas son tibbr Community 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 y anteriores; 6.0.0; 6.0.1; 7.0.0."
    }
  ],
  "lastModified": "2026-06-17T01:20:41.157",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32716CA0-AC00-40B2-BBF7-898E69712A66",
              "versionEndIncluding": "5.2.1"
            },
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:6.0.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72376148-EE12-40BD-9333-F62157FA456A"
            },
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:6.0.1:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A3693AF-9265-4F5C-8B5E-7DC1633E8193"
            },
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:7.0.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7E5DE4E-D81B-4EE5-AC6D-EB570ED0F1F8"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "304DD405-595E-47C9-8465-724E89CA0AD6",
              "versionEndIncluding": "5.2.1"
            },
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:6.0.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "357596C7-3A7F-4A57-846B-4B042A6BB482"
            },
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:6.0.1:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3145EF91-6E73-4BD5-9492-12ABDAFDE5CF"
            },
            {
              "criteria": "cpe:2.3:a:tibco:tibbr:7.0.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89BCF16F-E353-4531-B3D4-4D5E92790E76"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@tibco.com"
}