Description
The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.
Published: 2023-02-22
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX versions 5.9.21 and below: update to version 5.9.22 or later TIBCO EBX versions 6.0.11 and below: update to version 6.0.12 or later TIBCO Product and Service Catalog powered by TIBCO EBX versions 1.2.0 and below: update to version 1.2.1 or later

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-44757 The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.
History

No history.

Subscriptions

Tibco Ebx Product And Service Catalog Powered By Tibco Ebx
cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-08-03T12:49:43.191Z

Reserved: 2022-09-26T00:00:00.000Z

Link: CVE-2022-41565

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-02-22T18:15:10.447

Modified: 2024-11-21T07:23:24.400

Link: CVE-2022-41565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses