First published: Tue Aug 16 2022(Updated: )
The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science - Workbench: versions 14.0.0 and below, TIBCO Statistica: versions 14.0.0 and below, TIBCO Statistica - Estore Edition: versions 14.0.0 and below, and TIBCO Statistica Trial: versions 14.0.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Data Science - Workbench | <14.0.1 | |
TIBCO Statistica | <14.0.1 | |
TIBCO Statistica | <14.0.1 | |
TIBCO Statistica | <14.0.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO Data Science - Workbench versions 14.0.0 and below: update to version 14.0.1 or later TIBCO Statistica versions 14.0.0 and below: update to version 14.0.1 or later TIBCO Statistica - Estore Edition versions 14.0.0 and below: update to version 14.0.1 or later TIBCO Statistica Trial versions 14.0.0 and below: update to version 14.0.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30575 is a vulnerability in the Web Console component of TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial that allows for easily exploitable Reflected Cross Site Scripting (XSS) attacks.
CVE-2022-30575 has a severity level of high, with a severity value of 5.4.
CVE-2022-30575 affects TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial.
CVE-2022-30575 can be exploited through Reflected Cross Site Scripting (XSS) attacks.
To mitigate the risk of CVE-2022-30575, it is recommended to update to a version beyond 14.0.1 of the affected software applications.