First published: Thu May 25 2023(Updated: )
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application access to read system files that are accessible to the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.
Credit: security@tibco.com security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO EBX Add-ons | <4.5.17 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX Add-ons versions 4.5.16 and below: update to version 4.5.17 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26215 is a vulnerability in the server component of TIBCO Software Inc.'s TIBCO EBX Add-ons that allows an attacker with low-privileged application access to read system files.
CVE-2023-26215 has a severity rating of 6.5 (high).
TIBCO EBX Add-ons versions 4.5.16 and below are affected by CVE-2023-26215.
An attacker with low-privileged application access can exploit CVE-2023-26215 to read system files accessible to the web server.
At the moment, there is no known fix for CVE-2023-26215. It is recommended to follow the official advisories and updates from TIBCO Software Inc.