CVE-2022-41567: TIBCO BusinessConnect Stored XSS Vulnerability
The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-41567?
CVE-2022-41567 is a vulnerability in the BusinessConnect UI component of TIBCO BusinessConnect that allows a low privileged attacker to execute a cross-site scripting (XSS) attack.
How severe is CVE-2022-41567?
CVE-2022-41567 has a severity score of 5.4 (high).
Which version of TIBCO BusinessConnect is affected by CVE-2022-41567?
Versions up to and excluding 7.3.1 of TIBCO BusinessConnect are affected by CVE-2022-41567.
How can the vulnerability CVE-2022-41567 be exploited?
The vulnerability CVE-2022-41567 can be exploited by a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system.
How can I fix CVE-2022-41567?
To fix CVE-2022-41567, it is recommended to update TIBCO BusinessConnect to a version that is not affected, once it becomes available.