First published: Wed Jan 19 2022(Updated: )
The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons, TIBCO EBX Add-ons, and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.124 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, 5.9.14, and 5.9.15, TIBCO EBX: versions 6.0.0, 6.0.1, 6.0.2, and 6.0.3, TIBCO EBX Add-ons: versions 3.20.18 and below, TIBCO EBX Add-ons: versions 4.1.0, 4.2.0, 4.2.1, 4.2.2, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5, and 4.5.6, TIBCO EBX Add-ons: versions 5.0.0, 5.0.1, 5.1.0, 5.1.1, and 5.2.0, and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.1.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO EBX | <5.8.125 | |
TIBCO EBX | =5.9.3 | |
TIBCO EBX | =5.9.4 | |
TIBCO EBX | =5.9.5 | |
TIBCO EBX | =5.9.6 | |
TIBCO EBX | =5.9.7 | |
TIBCO EBX | =5.9.8 | |
TIBCO EBX | =5.9.9 | |
TIBCO EBX | =5.9.10 | |
TIBCO EBX | =5.9.11 | |
TIBCO EBX | =5.9.12 | |
TIBCO EBX | =5.9.13 | |
TIBCO EBX | =5.9.14 | |
TIBCO EBX | =5.9.15 | |
TIBCO EBX | =6.0.0 | |
TIBCO EBX | =6.0.1 | |
TIBCO EBX | =6.0.2 | |
TIBCO EBX | =6.0.3 | |
TIBCO EBX Add-ons | <3.20.19 | |
TIBCO EBX Add-ons | =4.1.0 | |
TIBCO EBX Add-ons | =4.2.0 | |
TIBCO EBX Add-ons | =4.2.1 | |
TIBCO EBX Add-ons | =4.2.2 | |
TIBCO EBX Add-ons | =4.3.0 | |
TIBCO EBX Add-ons | =4.3.1 | |
TIBCO EBX Add-ons | =4.3.2 | |
TIBCO EBX Add-ons | =4.3.3 | |
TIBCO EBX Add-ons | =4.3.4 | |
TIBCO EBX Add-ons | =4.4.0 | |
TIBCO EBX Add-ons | =4.4.1 | |
TIBCO EBX Add-ons | =4.4.2 | |
TIBCO EBX Add-ons | =4.4.3 | |
TIBCO EBX Add-ons | =4.5.0 | |
TIBCO EBX Add-ons | =4.5.1 | |
TIBCO EBX Add-ons | =4.5.2 | |
TIBCO EBX Add-ons | =4.5.3 | |
TIBCO EBX Add-ons | =4.5.4 | |
TIBCO EBX Add-ons | =4.5.5 | |
TIBCO EBX Add-ons | =4.5.6 | |
TIBCO EBX Add-ons | =5.0.0 | |
TIBCO EBX Add-ons | =5.0.1 | |
TIBCO EBX Add-ons | =5.1.0 | |
TIBCO EBX Add-ons | =5.1.1 | |
TIBCO EBX Add-ons | =5.2.0 | |
TIBCO Product and Service Catalog powered by TIBCO EBX | <1.2.0 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX versions 5.8.124 and below update to version 5.8.125 or later TIBCO EBX versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, 5.9.14, and 5.9.15 update to version 5.9.16 or later TIBCO EBX versions 6.0.0, 6.0.1, 6.0.2, and 6.0.3 update to version 6.0.4 or later TIBCO EBX Add-ons versions 3.20.18 and below update to version 3.20.19 or later TIBCO EBX Add-ons versions 4.1.0, 4.2.0, 4.2.1, 4.2.2, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5, and 4.5.6 update to version 4.5.7 or later TIBCO EBX Add-ons versions 5.0.0, 5.0.1, 5.1.0, 5.1.1, and 5.2.0 update to version 5.2.1 or later TIBCO Product and Service Catalog powered by TIBCO EBX versions 1.1.0 and below update to version 1.2.0 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22769 is a vulnerability found in the Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX Add-ons, and TIBCO Product and Service Catalog powered by TIBCO EBX.
CVE-2022-22769 has a severity rating of critical (9 out of 10).
Versions up to 5.8.125 of TIBCO EBX are affected by CVE-2022-22769.
To fix CVE-2022-22769, it is recommended to update TIBCO EBX to a version that is not affected by the vulnerability.
More information about CVE-2022-22769 can be found on TIBCO's advisory page: [link](https://www.tibco.com/support/advisories/2022/01/tibco-security-advisory-january-19-2022-tibco-ebx-2022-22769).