CVE-2023-26214: TIBCO BusinessConnect Reflected XSS Vulnerability
The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-26214?
CVE-2023-26214 is a vulnerability in the BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect.
What is the severity of CVE-2023-26214?
CVE-2023-26214 has a severity level of high (5.4).
What software is affected by CVE-2023-26214?
TIBCO BusinessConnect versions up to and excluding 7.3.1 are affected by CVE-2023-26214.
What is the CWE of CVE-2023-26214?
CVE-2023-26214 is categorized under CWE-79 (Improper Neutralization of Input During Web Page Generation).
How can I fix CVE-2023-26214?
To fix CVE-2023-26214, it is recommended to apply the latest patches and updates provided by TIBCO Software Inc.