Security Advisory Regarding TIBCO BPM Enterprise

Security Advisory Regarding TIBCO BPM Enterprise

book

Article ID: KB0107976

calendar_today

Updated On:

Products Versions
TIBCO BPM Enterprise (formerly TIBCO ActiveMatrix BPM) 4.3.1 and below

Description

TIBCO ActiveMatrix BPM Reflected Cross Site Scripting (XSS) vulnerability

  Original release date: May 17, 2022
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains difficult to exploit Reflected Cross Site
  Scripting (XSS) vulnerabilities that allow low privileged attackers with
  network access to execute scripts targeting the affected system or the
  victim's local system.

Impact

  In the worst case, if the victim is a privileged administrator, successful
  execution of these vulnerabilities can result in an attacker gaining full
  administrative access to the affected system.

  CVSS v3 Base Score: 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)

Environment

Products Affected TIBCO BPM Enterprise versions 4.3.1 and below TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric versions 4.3.1 and below The following component is affected: * Workspace client

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO BPM Enterprise versions 4.3.1 and below: update to version 4.3.2 or
    later

  TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric versions 4.3.1 and
    below: update to version 4.3.2 or later
 

Issue/Introduction

Security Advisory Regarding TIBCO BPM Enterprise Reflected Cross Site Scripting (XSS) vulnerability

Additional Information

  https://www.tibco.com/services/support/advisories
  CVE-2022-22775