CVE-2019-17332: TIBCO EBX Add-on For Digital Asset Manager Cross-Site Scripting Vulnerabilities
The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-17332?
CVE-2019-17332 is a vulnerability in the Digital Asset Manager Web Interface component of TIBCO EBX Add-ons, which allows authenticated users to perform stored cross-site scripting (XSS) attacks.
What is the severity of CVE-2019-17332?
The severity of CVE-2019-17332 is high, with a CVSS score of 5.4.
Which versions of TIBCO EBX Add-ons are affected by CVE-2019-17332?
Versions up to and including 3.20.13, 4.1.0, 4.2.0, 4.2.1, and 4.2.2 of TIBCO EBX Add-ons are affected by CVE-2019-17332.
How can authenticated users exploit CVE-2019-17332?
Authenticated users can exploit CVE-2019-17332 by performing stored cross-site scripting (XSS) attacks through the Digital Asset Manager Web Interface component of TIBCO EBX Add-ons.
How can the vulnerability in CVE-2019-17332 be fixed?
To fix the vulnerability in CVE-2019-17332, it is recommended to update to a version of TIBCO EBX Add-ons that is not affected by the vulnerability.