First published: Wed Feb 22 2023(Updated: )
The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO BusinessConnect | <7.3.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO BusinessConnect versions 7.3.0 and below: update to version 7.3.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41567 is a vulnerability in the BusinessConnect UI component of TIBCO BusinessConnect that allows a low privileged attacker to execute a cross-site scripting (XSS) attack.
CVE-2022-41567 has a severity score of 5.4 (high).
Versions up to and excluding 7.3.1 of TIBCO BusinessConnect are affected by CVE-2022-41567.
The vulnerability CVE-2022-41567 can be exploited by a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system.
To fix CVE-2022-41567, it is recommended to update TIBCO BusinessConnect to a version that is not affected, once it becomes available.