Critical severity9.9NVD Advisory· Published Aug 8, 2019· Updated Jun 17, 2026
CVE-2019-11208
CVE-2019-11208
Description
The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint, when the implementation uses multiple scopes. This issue affects: TIBCO Software Inc.'s TIBCO API Exchange Gateway version 2.3.1 and prior versions, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric version 2.3.1 and prior versions.
Affected products
6cpe:2.3:a:tibco:api_exchange_gateway:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:tibco:api_exchange_gateway:*:*:*:*:*:*:*:*range: <=2.3.1
- cpe:2.3:a:tibco:api_exchange_gateway:*:*:*:*:*:silver_fabric:*:*range: <=2.3.1
- (no CPE)range: 2.3.1 and prior
- (no CPE)range: <=2.3.1
2.3.1 and prior+ 1 more
- (no CPE)range: 2.3.1 and prior
- (no CPE)range: <=2.3.1
Patches
Vulnerability mechanics
References
2- www.tibco.com/services/support/advisoriesnvdVendor Advisory
- www.tibco.com/support/advisories/2019/08/tibco-security-advisory-august-7-2019-tibco-api-exchangenvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.