CVE-2019-17333: TIBCO EBX Exposes Cross-Site Scripting Vulnerability
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.1.fixS and below, versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-17333?
CVE-2019-17333 is a vulnerability in the Web server component of TIBCO Software Inc.'s TIBCO EBX that allows authenticated users to perform stored cross-site scripting (XSS) attacks.
What software versions are affected by CVE-2019-17333?
Versions 5.8.1.fixS and below, versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7 of TIBCO EBX are affected by CVE-2019-17333.
What is the severity of CVE-2019-17333?
CVE-2019-17333 has a severity rating of high.
How can an authenticated user exploit CVE-2019-17333?
An authenticated user can exploit CVE-2019-17333 by performing stored cross-site scripting (XSS) attacks.
Is there a fix for CVE-2019-17333?
Yes, TIBCO Software Inc. has released patches to address the vulnerability in its TIBCO EBX software. Please refer to the official advisories for more information.