First published: Tue Dec 06 2022(Updated: )
The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to exploit an open redirect on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: version 10.5.0.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Nimbus | =10.5.0 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO Nimbus version 10.5.0: update to version 10.5.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41559 is a vulnerability in the Web Client component of TIBCO Software Inc.'s TIBCO Nimbus that allows an unauthenticated attacker to exploit an open redirect on the affected system.
CVE-2022-41559 has a severity rating of critical, with a CVSS score of 9.3.
TIBCO Nimbus version 10.5.0 is affected by CVE-2022-41559.
An attacker with network access can exploit the open redirect vulnerability in the Web Client component of TIBCO Nimbus on an affected system.
To fix CVE-2022-41559, it is recommended to apply the necessary security patches provided by TIBCO Software Inc. and update to a version where the vulnerability is patched.