{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2023-26216", "ASSIGNER": "security@tibco.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.\n\n" } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "An application administrator without access to the underlying server could upload files that may be evaluated by the web server allowing them to perform actions with the privileges of the web server." } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "TIBCO Software Inc.", "product": { "product_data": [ { "product_name": "TIBCO EBX Add-ons", "version": { "version_data": [ { "version_affected": "<=", "version_name": "0", "version_value": "4.5.16" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://www.tibco.com/services/support/advisories", "refsource": "MISC", "name": "https://www.tibco.com/services/support/advisories" } ] }, "generator": { "engine": "Vulnogram 0.1.0-dev" }, "source": { "discovery": "UNKNOWN" }, "solution": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "

TIBCO has released updated versions of the affected components which address these issues.

TIBCO EBX Add-ons versions 4.5.16 and below: update to version 4.5.17 or later

" } ], "value": "TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO EBX Add-ons versions 4.5.16 and below: update to version 4.5.17 or later\n\n" } ], "impact": { "cvss": [ { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.1, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H", "version": "3.1" } ] } }