CVE-2019-17339

MEDIUM

TIBCO Silver Fabric < 6.0.0 - Authenticated Cross-Site Scripting via VirtualRouter URL

Title source: llm
STIX 2.1

Description

The VirtualRouter component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that theoretically allows an attacker to inject scripts via URLs. The attacker could theoretically social engineer an authenticated user into submitting the URL, thus executing the script on the affected system with the privileges of the user. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fabric: versions 6.0.0 and below.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www.tibco.com/services/support/advisories

Scores

CVSS v3 6.8
EPSS 0.0027
EPSS Percentile 50.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

Status published
Products (1)
tibco/silver_fabric < 6.0.0
Published Aug 11, 2020
Tracked Since Feb 18, 2026