CVE-2022-22778
TIBCO BusinessConnect Trading Community Management Cross-Site Request Forgery Vulnerability
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
18 may 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
TIBCO Software Inc. · TIBCO BusinessConnect Trading Community Management¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →