First published: Wed Jul 19 2023(Updated: )
The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permissions and network access to the EBX server to execute arbitrary SQL statements on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.17 and below, versions 5.6.2 and below, version 6.1.0.
Credit: security@tibco.com security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO EBX Add-ons | <=4.5.17 | |
TIBCO EBX Add-ons | >=5.0.0<=5.6.2 | |
TIBCO EBX Add-ons | =6.1.0 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX Add-ons versions 4.5.17 and below: update to version 4.5.18 or later TIBCO EBX Add-ons versions 5.6.2 and below: update to version 5.6.3 or later TIBCO EBX Add-ons version 6.1.0: update to version 6.1.1 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26217 is a vulnerability in the Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons.
CVE-2023-26217 has a severity score of 8.8, which is considered high.
A low privileged user with import permissions and network access to the EBX server can exploit CVE-2023-26217 to execute arbitrary SQL statements on the affected system.
Versions up to and including 4.5.17, versions between 5.0.0 and 5.6.2 (inclusive), and version 6.1.0 of TIBCO EBX Add-ons are affected by CVE-2023-26217.
To fix CVE-2023-26217, it is recommended to upgrade to a version of TIBCO EBX Add-ons that is not affected.