CVE-2022-30578: TIBCO EBX Add-ons Stored XSS vulnerability
The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 5.4.1 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-30578?
CVE-2022-30578 is a vulnerability in the Web Server component of TIBCO EBX Add-ons that allows an attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system.
How severe is CVE-2022-30578?
CVE-2022-30578 has a severity level of critical, with a CVSS score of 9.
What is the affected software for CVE-2022-30578?
The affected software for CVE-2022-30578 is TIBCO EBX Add-ons up to version 5.4.2.
How can an attacker exploit CVE-2022-30578?
An attacker with network access can exploit CVE-2022-30578 by executing Stored Cross Site Scripting (XSS) attacks on the vulnerable system.
Are there any references for CVE-2022-30578?
Yes, you can find more information about CVE-2022-30578 on TIBCO's advisories page: [link].