VulnerabilityModified
CVE-2015-8090
The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request.
MEDIUM 4.0EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- tibco/loglogic unity
- Source
- cve@mitre.org
References
- http://www.tibco.com/assets/bltec3263ae44ae601b/2015-005-advisory.txtVendor Advisory
- http://www.tibco.com/mk/advisory.jspVendor Advisory
- http://www.tibco.com/assets/bltec3263ae44ae601b/2015-005-advisory.txtVendor Advisory
- http://www.tibco.com/mk/advisory.jspVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.