CVE-2019-11207 describes multiple vulnerabilities within the web server component of TIBCO LogLogic Enterprise Virtual Appliance and TIBCO LogLogic Log Management Intelligence, affecting versions 6.2.1 and prior, as well as several specific LogLogic appliance models. These vulnerabilities include persistent and reflected cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The vulnerability carries a high CVSS score of 8.8, indicating a significant risk. An attacker could exploit these flaws remotely with low attack complexity, requiring user interaction, to achieve high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.2.1CPE matchmatch criteria | cpe:2.3:a:tibco:loglogic_enterprise_virtual_appliance:*:*:*:*:*:*:*:* | ||
<= 6.2.1CPE matchmatch criteria | cpe:2.3:a:tibco:loglogic_log_management_intelligence:*:*:*:*:*:*:*:* | ||
0.0.004CPE matchmatch criteria | cpe:2.3:o:tibco:loglogic_lx825_firmware:0.0.004:*:*:*:*:*:*:* | ||
0.0.004CPE matchmatch criteria | cpe:2.3:o:tibco:loglogic_lx4025_firmware:0.0.004:*:*:*:*:*:*:* | ||
0.0.004CPE matchmatch criteria | cpe:2.3:o:tibco:loglogic_mx3025_firmware:0.0.004:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.