8.7
CVE-2026-3912
- EPSS 0.04%
- Veröffentlicht 24.03.2026 20:44:06
- Zuletzt bearbeitet 25.03.2026 15:41:58
- Quelle security@tibco.com
- CVE-Watchlists
- Unerledigt
TIBCO ActiveMatrix BusinessWorks Injection Vulnerability
Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTibco
≫
Produkt
ActiveMatrix BusinessWorks
Default Statusunaffected
Version
6.12.0
Version <
HF1
Status
affected
Version
6.11.0
Version <
HF4
Status
affected
Version
6.10.0
Version <
HF6
Status
affected
Version
6.9.1
Version <
HF8
Status
affected
HerstellerTibco
≫
Produkt
Enterprise Administrator
Default Statusunaffected
Version
2.4.3
Version <
HF2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.105 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@tibco.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.