First published: Wed May 18 2022(Updated: )
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO BusinessConnect Trading Community Management | <6.1.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO BusinessConnect Trading Community Management versions 6.1.0 and below: update to version 6.1.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22776.
The severity of CVE-2022-22776 is high with a severity value of 5.4.
The affected software is TIBCO BusinessConnect Trading Community Management version 6.1.1.
The CWE of CVE-2022-22776 is CWE-79.
This vulnerability can be exploited by a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system.