CVE-2023-26215: TIBCO EBX® Add-ons Path Traversal
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application access to read system files that are accessible to the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-26215?
CVE-2023-26215 is a vulnerability in the server component of TIBCO Software Inc.'s TIBCO EBX Add-ons that allows an attacker with low-privileged application access to read system files.
How severe is CVE-2023-26215?
CVE-2023-26215 has a severity rating of 6.5 (high).
Which versions of TIBCO EBX Add-ons are affected by CVE-2023-26215?
TIBCO EBX Add-ons versions 4.5.16 and below are affected by CVE-2023-26215.
How can an attacker exploit CVE-2023-26215?
An attacker with low-privileged application access can exploit CVE-2023-26215 to read system files accessible to the web server.
Is there a fix for CVE-2023-26215?
At the moment, there is no known fix for CVE-2023-26215. It is recommended to follow the official advisories and updates from TIBCO Software Inc.