First published: Mon Dec 11 2017(Updated: )
Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via the users management panel of the web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Integrationmatters Njams | =3 | |
TIBCO BusinessWorks Process Monitor | <=3.0.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16789 is rated as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2017-16789, upgrade to Integration Matters nJAMS version 3.2.0 Hotfix 7 or later.
CVE-2017-16789 affects remote authenticated administrators using Integration Matters nJAMS 3 before 3.2.0 Hotfix 7 and TIBCO BusinessWorks Process Monitor versions up to 3.0.1.3.
CVE-2017-16789 is a cross-site scripting (XSS) vulnerability allowing the injection of arbitrary web scripts or HTML.
Yes, CVE-2017-16789 can be exploited remotely by authenticated administrators through the users management panel.