Overview
- Description
- The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.
- Source
- security@tibco.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:tibco:ebx:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E4509F3-99DB-44C0-B70E-E7A653548232", "versionEndExcluding": "5.9.22" }, { "criteria": "cpe:2.3:a:tibco:ebx:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A43D501-434D-4688-BCB0-4B87E23A5056", "versionEndExcluding": "6.0.12", "versionStartIncluding": "6.0.0" }, { "criteria": "cpe:2.3:a:tibco:product_and_service_catalog_powered_by_tibco_ebx:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DCC14B0-082E-4E28-89F9-CE28537C010A", "versionEndExcluding": "1.2.1" } ], "operator": "OR" } ] } ]