Security Advisory Regarding TIBCO BusinessConnect

Security Advisory Regarding TIBCO BusinessConnect

book

Article ID: KB0107944

calendar_today

Updated On:

Products Versions
TIBCO BusinessConnect 7.3.0

Description

TIBCO BusinessConnect Stored XSS Vulnerability

  Original release date: February 22, 2023
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains an easily exploitable vulnerability that
  allows a low privileged attacker with network access to execute a cross-site
  scripting (XSS) attack on the affected system.


Impact

  Successful execution of this attack could result in the ability to perform
  actions within the context of another user including reading, updating,
  inserting, or deleting data accessible to TIBCO BusinessConnect.

  CVSS v3.1 Base Score: 7.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N)
 

Issue/Introduction

Security Advisory Regarding TIBCO BusinessConnect Stored XSS Vulnerability

Environment

Products Affected   TIBCO BusinessConnect versions 7.3.0 and below   The following component is affected:     * BusinessConnect UI

Resolution

  TIBCO has released updated versions of the affected systems which address
  these issues:

  TIBCO BusinessConnect versions 7.3.0 and below: update to version 7.3.1 or
    later
 

Additional Information

  https://www.tibco.com/services/support/advisories
  CVE-2022-41567