Versio.io

CVE-2022-22769

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 19-01-2022 09:15
Last modified: - 26-01-2022 04:30
Total changes: - 3

Description

The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons, TIBCO EBX Add-ons, and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.124 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, 5.9.14, and 5.9.15, TIBCO EBX: versions 6.0.0, 6.0.1, 6.0.2, and 6.0.3, TIBCO EBX Add-ons: versions 3.20.18 and below, TIBCO EBX Add-ons: versions 4.1.0, 4.2.0, 4.2.1, 4.2.2, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5, and 4.5.6, TIBCO EBX Add-ons: versions 5.0.0, 5.0.1, 5.1.0, 5.1.1, and 5.2.0, and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.1.0 and below.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
High
Confidentiality
High
Integrity
Low
Privileges required
Changed
Scope
Required
User interaction
9.0
Base score
2.3
6.0
Exploitability score
Impact score
 

Verification logic

OR
vendor=tibco AND product=ebx AND versionEndExcluding=5.8.125
vendor=tibco AND product=ebx AND version=5.9.3
vendor=tibco AND product=ebx AND version=5.9.4
vendor=tibco AND product=ebx AND version=5.9.5
vendor=tibco AND product=ebx AND version=5.9.6
vendor=tibco AND product=ebx AND version=5.9.7
vendor=tibco AND product=ebx AND version=5.9.8
vendor=tibco AND product=ebx AND version=5.9.9
vendor=tibco AND product=ebx AND version=5.9.10
vendor=tibco AND product=ebx AND version=5.9.11
vendor=tibco AND product=ebx AND version=5.9.12
vendor=tibco AND product=ebx AND version=5.9.13
vendor=tibco AND product=ebx AND version=5.9.14
vendor=tibco AND product=ebx AND version=5.9.15
vendor=tibco AND product=ebx AND version=6.0.0
vendor=tibco AND product=ebx AND version=6.0.1
vendor=tibco AND product=ebx AND version=6.0.2
vendor=tibco AND product=ebx AND version=6.0.3
vendor=tibco AND product=ebx_add-ons AND versionEndExcluding=3.20.19
vendor=tibco AND product=ebx_add-ons AND version=4.1.0
vendor=tibco AND product=ebx_add-ons AND version=4.2.0
vendor=tibco AND product=ebx_add-ons AND version=4.2.1
vendor=tibco AND product=ebx_add-ons AND version=4.2.2
vendor=tibco AND product=ebx_add-ons AND version=4.3.0
vendor=tibco AND product=ebx_add-ons AND version=4.3.1
vendor=tibco AND product=ebx_add-ons AND version=4.3.2
vendor=tibco AND product=ebx_add-ons AND version=4.3.3
vendor=tibco AND product=ebx_add-ons AND version=4.3.4
vendor=tibco AND product=ebx_add-ons AND version=4.4.0
vendor=tibco AND product=ebx_add-ons AND version=4.4.1
vendor=tibco AND product=ebx_add-ons AND version=4.4.2
vendor=tibco AND product=ebx_add-ons AND version=4.4.3
vendor=tibco AND product=ebx_add-ons AND version=4.5.0
vendor=tibco AND product=ebx_add-ons AND version=4.5.1
vendor=tibco AND product=ebx_add-ons AND version=4.5.2
vendor=tibco AND product=ebx_add-ons AND version=4.5.3
vendor=tibco AND product=ebx_add-ons AND version=4.5.4
vendor=tibco AND product=ebx_add-ons AND version=4.5.5
vendor=tibco AND product=ebx_add-ons AND version=4.5.6
vendor=tibco AND product=ebx_add-ons AND version=5.0.0
vendor=tibco AND product=ebx_add-ons AND version=5.0.1
vendor=tibco AND product=ebx_add-ons AND version=5.1.0
vendor=tibco AND product=ebx_add-ons AND version=5.1.1
vendor=tibco AND product=ebx_add-ons AND version=5.2.0
vendor=tibco AND product=product_and_service_catalog_powered_by_tibco_ebx AND versionEndExcluding=1.2.0
 

Reference

 


Keywords

NVD

 

CVE-2022-22769

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.