Vulnerabilities > Tibco > Activematrix Businessworks > High

DATE CVE VULNERABILITY TITLE RISK
2019-04-09 CVE-2019-8990 Improper Authentication vulnerability in Tibco Activematrix Businessworks
The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is required.
network
high complexity
tibco CWE-287
8.1
2018-08-08 CVE-2018-12408 XXE vulnerability in Tibco products
The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages, and may disclose the contents of files accessible to a running BusinessWorks engine Affected releases are TIBCO Software Inc.
network
low complexity
tibco CWE-611
7.5