First published: Tue Aug 16 2022(Updated: )
The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Data Science - Workbench: versions 14.0.0 and below, TIBCO Statistica: versions 14.0.0 and below, TIBCO Statistica - Estore Edition: versions 14.0.0 and below, and TIBCO Statistica Trial: versions 14.0.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Data Science - Workbench | <14.0.1 | |
TIBCO Statistica | <14.0.1 | |
TIBCO Statistica | <14.0.1 | |
TIBCO Statistica | <14.0.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO Data Science - Workbench versions 14.0.0 and below: update to version 14.0.1 or later TIBCO Statistica versions 14.0.0 and below: update to version 14.0.1 or later TIBCO Statistica - Estore Edition versions 14.0.0 and below: update to version 14.0.1 or later TIBCO Statistica Trial versions 14.0.0 and below: update to version 14.0.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30576 is a vulnerability in the Web Console component of TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial.
CVE-2022-30576 has a severity rating of 5.4 which is considered high.
An attacker with low privileges and network access can exploit CVE-2022-30576 to execute Stored Cross Site Scripting attacks.
TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial versions up to 14.0.1 are affected by CVE-2022-30576.
To mitigate CVE-2022-30576, it is recommended to update the affected software to a version beyond 14.0.1.