First published: Wed May 18 2022(Updated: )
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO BusinessConnect Trading Community Management | <6.1.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO BusinessConnect Trading Community Management versions 6.1.0 and below: update to version 6.1.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22778 is a vulnerability in the Web Server component of TIBCO BusinessConnect Trading Community Management that allows an unauthenticated attacker to execute Cross-Site Request Forgery (CSRF) attacks.
CVE-2022-22778 has a severity rating of 8.8, which is considered high.
CVE-2022-22778 affects TIBCO BusinessConnect Trading Community Management versions up to and excluding 6.1.1.
An unauthenticated attacker with network access can exploit CVE-2022-22778 to execute CSRF attacks on the affected system.
Yes, TIBCO Software Inc. has released a security advisory with instructions on how to mitigate the vulnerability. Please refer to the provided links for more information.