"value":"TIBCO would like to extend its appreciation to Javier Sánchez Ávila of Entelgy Innotec Security for discovery of this vulnerability."
}
],
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 6.0.0 through 6.0.8."
"value":"Successful execution of these vulnerabilities will result in an attacker being able to execute commands with the privileges of the affected user."
"value":"TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO EBX versions 6.0.0 through 6.0.8: update to version 6.0.9 or later"