First published: Wed Feb 22 2023(Updated: )
The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO EBX | <5.9.22 | |
TIBCO EBX | >=6.0.0<6.0.12 | |
TIBCO Product and Service Catalog powered by TIBCO EBX | <1.2.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX versions 5.9.21 and below: update to version 5.9.22 or later TIBCO EBX versions 6.0.11 and below: update to version 6.0.12 or later TIBCO Product and Service Catalog powered by TIBCO EBX versions 1.2.0 and below: update to version 1.2.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41565 is a vulnerability in the Web Application component of TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX that allows for a stored XSS attack.
CVE-2022-41565 has a severity score of 5.4, which is considered high.
The affected software versions include TIBCO EBX up to version 5.9.22, TIBCO EBX versions 6.0.0 to 6.0.12, and TIBCO Product and Service Catalog powered by TIBCO EBX up to version 1.2.1.
A low privileged attacker with network access can exploit CVE-2022-41565 by executing a stored XSS attack on the affected system.
You can find more information about CVE-2022-41565 in the advisory provided by TIBCO Software Inc. at the following link: [https://www.tibco.com/services/support/advisories]