First published: Tue Nov 14 2023(Updated: )
The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO EBX | <=5.0.0 | |
TIBCO EBX | >=5.1.1<5.9.23 | |
TIBCO EBX | >=6.0.0<6.0.14 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX versions 5.9.22 and below: update to version 5.9.23 or later TIBCO EBX versions 6.0.13 and below: update to version 6.0.14 or later TIBCO Product and Service Catalog powered by TIBCO EBX versions 5.0.0 and below: update to version 5.1.0 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26222 is a Cross-site Scripting (XXS) vulnerability found in the Web Application component of TIBCO EBX and TIBCO Product and Service Catalog.
CVE-2023-26222 has a severity rating of 8.7, which is considered high.
CVE-2023-26222 affects TIBCO EBX versions 5.0.0 up to and including 5.9.23, as well as versions 6.0.0 up to and including 6.0.14.
CVE-2023-26222 is associated with CWE-79.
To fix CVE-2023-26222, it is recommended to upgrade TIBCO EBX to a version that is not affected by the vulnerability.