CVE-2021-23271: TIBCO EBX Cross Site Scripting (XSS)
Published Feb 2, 2021
·Updated
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.12 and below.
Affected Software
1 affected component
TIBCO EBX<=5.9.12
Remediation
Information
TIBCO has released updated versions of the affected components which address these issues.
TIBCO EBX versions 5.9.12 and below update to version 5.9.13 or higher
Event History
Feb 2, 2021
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this TIBCO EBX vulnerability?
The vulnerability ID for this TIBCO EBX vulnerability is CVE-2021-23271.
2
What is the severity of CVE-2021-23271?
The severity of CVE-2021-23271 is high with a severity value of 8.
3
What is the affected software for CVE-2021-23271?
The affected software for CVE-2021-23271 is TIBCO EBX version 5.9.12.
4
What is the vulnerability type for CVE-2021-23271?
The vulnerability type for CVE-2021-23271 is Stored Cross Site Scripting (XSS) attack.
5
How can a low privileged attacker exploit CVE-2021-23271?
A low privileged attacker with network access can execute a Stored Cross Site Scripting (XSS) attack on the affected system.