← Back

Tibco

tibco

226 CVEs • 179 products

Products (179)

Click to collapse
Toggle
Rendezvous
rendezvous
Jaspersoft
jaspersoft
Runtime Agent
runtime_agent
Ftl
ftl
Ebx
ebx
Ebx Add Ons
ebx_add-ons
Hawk
hawk
Administrator
administrator
Rtworks
rtworks
Slingshot
slingshot
Eftl
eftl
Activecatalog
activecatalog
Nimbus
nimbus
Tibbr
tibbr
Vault
vault
Activespaces
activespaces
Smart Pgm Fx
smart_pgm_fx
Substation Es
substation_es
Silver Fabric
silver_fabric
Statistica
statistica
Rendezvous Tx
rendezvous_tx
Smartsockets
smartsockets
Tibbr Service
tibbr_service
Businessevents
businessevents
Formvine
formvine
Silver Mobile
silver_mobile
Web Player
web_player
Analyst
analyst
Desktop
desktop
Deployment Kit
deployment_kit
Loglogic Unity
loglogic_unity

CVEs (226)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tibco
2Activecatalog
Collaborative Information Manager
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Session fixation vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to hijack web sessions v...Show more
Session fixation vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to hijack web sessions via unspecified vectors.Show less
1Tibco
2Activecatalog
Collaborative Information Manager
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to modify data or obtain sens...Show more
Unspecified vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.Show less
1Tibco
2Activecatalog
Collaborative Information Manager
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to inject arbi...Show more
Cross-site scripting (XSS) vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Tibco
2Activecatalog
Collaborative Information Manager
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allow remote attackers to execute arbitr...Show more
Multiple SQL injection vulnerabilities in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allow remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less
1Tibco
6Activematrix Bpm
Activematrix Businessworks Service EngineActivematrix Service Bus+3 more
Apr 29, 2026
Dec 17, 2010
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the ActiveMatrix Runtime component in TIBCO ActiveMatrix Service Grid 3.0.0, 3.0.1, and 3.1.0; ActiveMatrix Service Bus 3.0.0 and 3.0.1; ActiveMatrix BusinessWorks Service Engine 5.9.0; Activ...Show more
Unspecified vulnerability in the ActiveMatrix Runtime component in TIBCO ActiveMatrix Service Grid 3.0.0, 3.0.1, and 3.1.0; ActiveMatrix Service Bus 3.0.0 and 3.0.1; ActiveMatrix BusinessWorks Service Engine 5.9.0; ActiveMatrix BPM 1.0.1 and 1.0.2; Silver BPM Service 1.0.1; and Silver CAP Service 1.0.0 allows remote authenticated users to execute arbitrary code via vectors related to JMX connections.Show less
1Tibco
4Activematrix Businessworks Service Engine
Activematrix Service BusActivematrix Service Grid+1 more
Apr 29, 2026
Oct 26, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, a...Show more
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.Show less
1Tibco
1Administrator
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Unspecified vulnerability in TIBRepoServer5.jar in TIBCO Administrator 5.4.0 through 5.6.0, when JMS transport is used, allows remote authenticated users to execute arbitrary code on all domain nodes via vectors related...Show more
Unspecified vulnerability in TIBRepoServer5.jar in TIBCO Administrator 5.4.0 through 5.6.0, when JMS transport is used, allows remote authenticated users to execute arbitrary code on all domain nodes via vectors related to leveraging administrative credentials.Show less
1Tibco
1Runtime Agent
Apr 23, 2026
Jan 14, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain...Show more
The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.Show less
1Tibco
4Enterprise Message Service
RtworksSmartsockets+1 more
Apr 23, 2026
Apr 30, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks...Show more
Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and components, EMS Server (aka tibemsd), SmartMQ, iProcess Engine, ActiveMatrix products, and CA Enterprise Communicator, allows remote attackers to execute arbitrary code via "inbound data," as demonstrated by requests to the UDP interface of the RTserver component, and data injection into the TCP stream to tibemsd.Show less
1Tibco
4Hawk
Iprocess EngineMainframe Service Tracker+1 more
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1; Runtime Agent (TRA) before 5.6.0; iProcess Engine 10.3.0 through 10.6.2 and 11....Show more
Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1; Runtime Agent (TRA) before 5.6.0; iProcess Engine 10.3.0 through 10.6.2 and 11.0.0; and Mainframe Service Tracker before 1.1.0 might allow remote attackers to execute arbitrary code via a crafted message.Show less
1Tibco
2Enterprise Message Service
Iprocess Engine
Apr 23, 2026
Apr 11, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow remote attackers to execute arbitrary code via a crafted message to the EMS serv...Show more
Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow remote attackers to execute arbitrary code via a crafted message to the EMS server.Show less
1Tibco
8Adapter Files Z Os
HawkIprocess Engine+5 more
Apr 23, 2026
Apr 11, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO products, allow remote attackers to execute arbitrary code via a crafted message.
1Tibco
3Enterprise Message Service
RtworksSmartsockets Rtserver
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted re...Show more
Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow.Show less
1Tibco
3Enterprise Message Service
RtworksSmartsockets Rtserver
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that...Show more
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.Show less
1Tibco
3Enterprise Message Service
RtworksSmartsockets Rtserver
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co...Show more
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that control loop operations related to memory.Show less
1Tibco
3Enterprise Message Service
RtworksSmartsockets Rtserver
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that...Show more
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers.Show less
1Tibco
1Smart Pgm Fx
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple stack-based buffer overflows in TIBCO SmartPGM FX allow remote attackers to execute arbitrary code or cause a denial of service (service stop and file-transfer outage) via unspecified vectors. NOTE: as of 20071...Show more
Multiple stack-based buffer overflows in TIBCO SmartPGM FX allow remote attackers to execute arbitrary code or cause a denial of service (service stop and file-transfer outage) via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less
1Tibco
1Smart Pgm Fx
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory w...Show more
Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less
1Tibco
1Rendezvous
Apr 23, 2026
Aug 3, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
TIBCO Rendezvous (RV) 7.5.2 does not protect confidentiality or integrity of inter-daemon communication, which allows remote attackers to capture and spoof traffic.
1Tibco
1Rendezvous
Apr 23, 2026
Aug 3, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
rvd in TIBCO Rendezvous (RV) 7.5.2, when -no-lead-wc is omitted, might allow remote attackers to cause a denial of service (network instability) via a subject name with a leading (1) '*' (asterisk) or (2) '>' (greater th...Show more
rvd in TIBCO Rendezvous (RV) 7.5.2, when -no-lead-wc is omitted, might allow remote attackers to cause a denial of service (network instability) via a subject name with a leading (1) '*' (asterisk) or (2) '>' (greater than) wildcard character.Show less