| Products | Versions | 
|---|---|
| TIBCO EBX Add-ons | 5.6.0 and below | 
TIBCO EBX Add-ons Cross Site Scripting (XXS) Vulnerability
  Original release date: February 22, 2023
  Last revised: ---
  Source: TIBCO Software Inc.
Description
  The component listed above contains an easily exploitable vulnerability that
  allows a low privileged attacker with network access to execute stored XSS on
  the affected system.
Impact
  The impact of this vulnerability includes the theoretical possibility of
  unauthorized access  to TIBCO EBX® Add-ons data. This includes the ability to
  update, insert, or delete data.
  CVSS v3.1 Base Score: 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N)