First published: Wed Feb 22 2023(Updated: )
The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO BusinessConnect | <7.3.1 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO BusinessConnect versions 7.3.0 and below: update to version 7.3.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26214 is a vulnerability in the BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect.
CVE-2023-26214 has a severity level of high (5.4).
TIBCO BusinessConnect versions up to and excluding 7.3.1 are affected by CVE-2023-26214.
CVE-2023-26214 is categorized under CWE-79 (Improper Neutralization of Input During Web Page Generation).
To fix CVE-2023-26214, it is recommended to apply the latest patches and updates provided by TIBCO Software Inc.