First published: Tue Feb 15 2022(Updated: )
The Web Server component of TIBCO Software Inc.'s TIBCO AuditSafe contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute API methods on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO AuditSafe: versions 1.1.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO AuditSafe | <1.1.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO AuditSafe versions 1.1.0 and below update to version 1.1.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22770.
CVE-2022-22770 has a severity rating of 9.8 (Critical).
TIBCO Software Inc.'s TIBCO AuditSafe versions 1.1.0 up to exclusive version 1.1.1 are affected by CVE-2022-22770.
An unauthenticated attacker with network access can exploit CVE-2022-22770 by executing API methods on the affected system.
To fix CVE-2022-22770, it is recommended to update to a version of TIBCO AuditSafe that is not affected by the vulnerability. Please refer to the TIBCO Software Inc. advisory for more information.