First published: Wed Sep 21 2022(Updated: )
The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 5.4.1 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO EBX Add-ons | <5.4.2 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX Add-ons versions 5.4.1 and below: update to version 5.4.2 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30578 is a vulnerability in the Web Server component of TIBCO EBX Add-ons that allows an attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system.
CVE-2022-30578 has a severity level of critical, with a CVSS score of 9.
The affected software for CVE-2022-30578 is TIBCO EBX Add-ons up to version 5.4.2.
An attacker with network access can exploit CVE-2022-30578 by executing Stored Cross Site Scripting (XSS) attacks on the vulnerable system.
Yes, you can find more information about CVE-2022-30578 on TIBCO's advisories page: [link].