CVE-2019-17331: TIBCO EBX Add-on For Data Exchange Cross-Site Scripting Vulnerabilities
Published Nov 12, 2019
·Updated
The Data Exchange Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, version 4.1.0.
Affected Software
2 affected components
TIBCO EBX Add-ons<=3.20.13
TIBCO EBX Add-ons=4.1.0
Remediation
Information
TIBCO has released updated versions of the affected components which address these issues.
TIBCO EBX Add-ons versions 3.20.13 and below update to version 3.20.14 or higher
TIBCO EBX Add-ons version 4.1.0 update to version 4.2.0 or higher
Event History
Nov 12, 2019
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-17331.
2
What is the severity of CVE-2019-17331?
CVE-2019-17331 has a severity of high.
3
Which software versions are affected by CVE-2019-17331?
The affected software versions are TIBCO EBX Add-ons up to and including version 3.20.13 and version 4.1.0.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-17331?
The Common Weakness Enumeration (CWE) ID for CVE-2019-17331 is CWE-79.
5
How can I fix CVE-2019-17331?
To fix CVE-2019-17331, upgrade to a version of TIBCO EBX Add-ons that is not affected by the vulnerability.