CVE-2023-26222
TIBCO EBX Cross-site Scripting (XXS) Vulnerability
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.7EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
14 nov 2023Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Produtos afetados
TIBCO Software Inc. · TIBCO EBXTIBCO Software Inc. · TIBCO Product and Service Catalog powered by TIBCO EBXQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →