CVE-2022-41565

HIGH

TIBCO EBX < 5.9.22 and TIBCO Product and Service Catalog powered by TIBCO EBX < 1.2.1 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.21 and below, versions 6.0.11 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.2.0 and below.

References (1)

Core 1
Core References

Scores

CVSS v3 8.7
EPSS 0.0071
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-79
Status published
Products (2)
tibco/ebx < 5.9.22
tibco/product_and_service_catalog_powered_by_tibco_ebx < 1.2.1
Published Feb 22, 2023
Tracked Since Feb 18, 2026