CVE-2023-26216: TIBCO EBX Add-ons Arbitrary File Write
Published May 25, 2023
·Updated
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.
Affected Software
1 affected component
TIBCO EBX Add-ons<4.5.17
Remediation
Information
TIBCO has released updated versions of the affected components which address these issues.
TIBCO EBX Add-ons versions 4.5.16 and below: update to version 4.5.17 or later
Event History
May 25, 2023
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this TIBCO EBX Add-ons vulnerability?
The vulnerability ID is CVE-2023-26216.
2
What is the severity of CVE-2023-26216?
The severity of CVE-2023-26216 is critical with a severity value of 7.2.
3
What is the affected software version range for CVE-2023-26216?
The affected software versions for CVE-2023-26216 are TIBCO EBX Add-ons versions 4.5.16 and below.
4
How does the vulnerability in TIBCO EBX Add-ons allow attackers to exploit it?
The vulnerability allows an attacker to upload files to a directory accessible by the web server.
5
Where can I find more information about this TIBCO EBX Add-ons vulnerability?
More information can be found at the following link: https://www.tibco.com/services/support/advisories