CVE-2021-35499: TIBCO Nimbus Stored Cross-site Scripting (XSS) vulnerabilities
The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.4.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35499?
CVE-2021-35499 is a vulnerability in the Web Reporting component of TIBCO Nimbus, which allows for stored cross-site scripting (XSS) attacks.
What is the severity of CVE-2021-35499?
The severity of CVE-2021-35499 is high, with a CVSS score of 5.4.
How does CVE-2021-35499 affect TIBCO Nimbus?
CVE-2021-35499 affects TIBCO Nimbus version 10.4.0, allowing low privileged attackers to exploit stored XSS vulnerabilities.
How can CVE-2021-35499 be exploited?
CVE-2021-35499 can be exploited by a low privileged attacker to execute scripts on the affected system or target the victim through social engineering.
Is there a fix available for CVE-2021-35499?
Yes, TIBCO Software Inc. has released a security advisory with patches to address CVE-2021-35499. Please refer to the TIBCO website for more information.