First published: Wed Feb 19 2020(Updated: )
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.1.fixS and below, versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO EBX | <5.8.1 | |
TIBCO EBX | >=5.9.3<=5.9.7 | |
TIBCO EBX | =5.8.1 | |
TIBCO EBX | =5.8.1-fixr | |
TIBCO EBX | =5.8.1-fixs |
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX versions 5.8.1.fixS and below update to version 5.8.1.fixT or higher TIBCO EBX versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7 update to version 5.9.8 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17333 is a vulnerability in the Web server component of TIBCO Software Inc.'s TIBCO EBX that allows authenticated users to perform stored cross-site scripting (XSS) attacks.
Versions 5.8.1.fixS and below, versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7 of TIBCO EBX are affected by CVE-2019-17333.
CVE-2019-17333 has a severity rating of high.
An authenticated user can exploit CVE-2019-17333 by performing stored cross-site scripting (XSS) attacks.
Yes, TIBCO Software Inc. has released patches to address the vulnerability in its TIBCO EBX software. Please refer to the official advisories for more information.