Medium severity5.0NVD Advisory· Published Nov 10, 2020· Updated Jun 17, 2026
CVE-2020-27146
CVE-2020-27146
Description
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human interaction from an authenticated user other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser): versions 11.6.0 and below.
Affected products
3cpe:2.3:a:tibco:iprocess_workspace_browser:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:tibco:iprocess_workspace_browser:*:*:*:*:*:*:*:*range: <=11.6.0
- (no CPE)range: <=11.6.0
- Range: unspecified
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.