Security Advisory regarding TIBCO EBX

Security Advisory regarding TIBCO EBX

book

Article ID: KB0107935

calendar_today

Updated On:

Products Versions
TIBCO EBX 5.9.22 and below, 6.0.13 and below

Description

TIBCO Security Advisory: November 14, 2023 - TIBCO EBX - CVE-2023-26222

TIBCO EBX Cross-site Scripting (XXS) Vulnerability

Original release date: November 14, 2023
Last revised: —
CVE-2023-26222
Source: TIBCO Software Inc.

 

Products Affected

 
  • TIBCO EBX versions 5.9.22 and below
  • TIBCO EBX versions 6.0.13 and below
  • TIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below
 

The following component is affected:

  • Web Application

Description

 

The component listed above contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. 

 

Impact

 

The impact of this vulnerability includes the theoretical possibility resulting in unauthorized ability to update, insert or delete TIBCO EBX® data.

CVSS v3.1 Base Score: 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N)

Environment

Products Affected TIBCO EBX versions 5.9.22 and below TIBCO EBX versions 6.0.13 and below TIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below The following component is affected: - Web Application

Resolution

TIBCO has released updated versions of the affected systems which address this issue:

  • TIBCO EBX versions 5.9.22 and below: update to version 5.9.23 or later
  • TIBCO EBX versions 6.0.13 and below: update to version 6.0.14 or later
  • TIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below: update to version 5.1.0 or later

Issue/Introduction

Security Advisory regarding TIBCO EBX Cross-site Scripting (XXS) Vulnerability

Additional Information

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26222
https://www.tibco.com/support/advisories/2023/11/tibco-security-advisory-november-14-2023-tibco-ebx-cve-2023-26222