CVE-2022-22778: TIBCO BusinessConnect Trading Community Management Cross-Site Request Forgery Vulnerability
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22778?
CVE-2022-22778 is a vulnerability in the Web Server component of TIBCO BusinessConnect Trading Community Management that allows an unauthenticated attacker to execute Cross-Site Request Forgery (CSRF) attacks.
What is the severity of CVE-2022-22778?
CVE-2022-22778 has a severity rating of 8.8, which is considered high.
How does CVE-2022-22778 affect TIBCO BusinessConnect Trading Community Management?
CVE-2022-22778 affects TIBCO BusinessConnect Trading Community Management versions up to and excluding 6.1.1.
How can an attacker exploit CVE-2022-22778?
An unauthenticated attacker with network access can exploit CVE-2022-22778 to execute CSRF attacks on the affected system.
Is there a fix available for CVE-2022-22778?
Yes, TIBCO Software Inc. has released a security advisory with instructions on how to mitigate the vulnerability. Please refer to the provided links for more information.