"TITLE":"TIBCO EBX Cross Site Scripting (XSS) Vulnerability"
},
"affects":{
"vendor":{
"vendor_data":[
{
"product":{
"product_data":[
{
"product_name":"TIBCO EBX",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_value":"5.9.21"
},
{
"version_affected":"<=",
"version_value":"6.0.11"
}
]
}
},
{
"product_name":"TIBCO Product and Service Catalog powered by TIBCO EBX",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_value":"1.2.0"
}
]
}
}
]
},
"vendor_name":"TIBCO Software Inc."
}
]
}
},
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below."
"value":"The impact of this vulnerability includes the theoretical possibility resulting in unauthorized ability to update, insert or delete TIBCO EBX data."
"value":"TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO EBX versions 5.9.21 and below: update to version 5.9.22 or later\nTIBCO EBX versions 6.0.11 and below: update to version 6.0.12 or later\nTIBCO Product and Service Catalog powered by TIBCO EBX versions 1.2.0 and below: update to version 1.2.1 or later"