Security Advisory regarding TIBCO BusinessConnect Trading Community Management

Security Advisory regarding TIBCO BusinessConnect Trading Community Management

book

Article ID: KB0107973

calendar_today

Updated On:

Products Versions
TIBCO BusinessConnect Trading Community Management 6.1.0

Description

TIBCO BusinessConnect Trading Community Management Stored Cross Site Scripting
Vulnerability

  Original release date: May 18, 2022
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains easily exploitable vulnerabilities that
  allows a low privileged attacker with network access to execute Stored Cross
  Site Scripting (XSS) on the affected system. A successful attack using these
  vulnerabilities requires human interaction from a person other than the
  attacker.


Impact

  In the worst case, if the victim is a privileged administrator, successful
  execution of these vulnerabilities can result in an attacker gaining full
  administrative access to the affected system.

  CVSS v3 Base Score: 8.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)

Environment

Products Affected TIBCO BusinessConnect Trading Community Management versions 6.1.0 and below The following component is affected: * Web Server

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO BusinessConnect Trading Community Management versions 6.1.0 and below:
    update to version 6.1.1 or later

Issue/Introduction

Security Advisory regarding TIBCO BusinessConnect Trading Community Management Stored Cross Site Scripting Vulnerability

Additional Information

  https://www.tibco.com/services/support/advisories
  CVE-2022-22776