CVE-2024-10218

CVSS 3.1 Score 5.2 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024

Summary

CVE-2024-10218 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting TIBCO Hawk and TIBCO Operational Intelligence. The issue lies in the mar.jar component of the Monitoring Archive Utility (MAR Utility), specifically in monitoringconsolecommon.jar. An attacker can exploit this vulnerability by injecting malicious scripts into web pages viewed by other users, potentially stealing sensitive information or taking control of their sessions. The impact of the attack can extend beyond the affected application, posing a significant risk to the entire organization's security. It is recommended that users update their software to the latest version, which includes a patch for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share