CVE-2022-30575
HIGHTIBCO Data Science - Workbench and Statistica < 14.0.1 - Reflected Cross-Site Scripting
Title source: llmDescription
The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science - Workbench: versions 14.0.0 and below, TIBCO Statistica: versions 14.0.0 and below, TIBCO Statistica - Estore Edition: versions 14.0.0 and below, and TIBCO Statistica Trial: versions 14.0.0 and below.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.tibco.com/services/support/advisories
Vendor Advisory x_refsource_confirm
https://www.tibco.com/support/advisories/2022/08/tibco-security-advisory-august-16-2022-tibco-statistica-cve-2022-30575
Scores
CVSS v3
7.3
EPSS
0.0062
EPSS Percentile
70.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Details
CWE
CWE-79
Status
published
Products (2)
tibco/data_science_-_workbench
< 14.0.1
tibco/statistica
< 14.0.1 (3 CPE variants)
Published
Aug 16, 2022
Tracked Since
Feb 18, 2026