The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-7743 The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2.
Fixes

Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX Add-ons versions 3.20.13 and below update to version 3.20.14 or higher TIBCO EBX Add-ons versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2 update to version 4.3.0 or higher


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-16T20:37:36.265Z

Reserved: 2019-10-07T00:00:00

Link: CVE-2019-17332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-12T20:15:12.263

Modified: 2024-11-21T04:32:06.270

Link: CVE-2019-17332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses