CVE-2022-41565
TIBCO EBX Cross Site Scripting (XSS) Vulnerability
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
22 Feb 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Affected products
TIBCO Software Inc. · TIBCO EBXTIBCO Software Inc. · TIBCO Product and Service Catalog powered by TIBCO EBXWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →