CVE-2026-3912 PUBLISHED

TIBCO ActiveMatrix BusinessWorks Injection Vulnerability

Assigner: tibco
Reserved: 11.03.2026 Published: 24.03.2026 Updated: 25.03.2026

Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSS Score: 8.7

Product Status

Vendor Tibco
Product ActiveMatrix BusinessWorks
Versions Default: unaffected
  • affected from 6.12.0 to HF1 (excl.)
  • affected from 6.11.0 to HF4 (excl.)
  • affected from 6.10.0 to HF6 (excl.)
  • affected from 6.9.1 to HF8 (excl.)
Vendor Tibco
Product Enterprise Administrator
Versions Default: unaffected
  • affected from 2.4.3 to HF2 (excl.)

References