Lucene search

K
cveTibcoCVE-2022-30571
HistoryAug 02, 2022 - 5:15 p.m.

CVE-2022-30571

2022-08-0217:15:10
CWE-79
tibco
web.nvd.nist.gov
46
2
cve-2022-30571
tibco
software
iway service manager
xss
vulnerability
nvd
network access

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

22.7%

The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim’s local system. Affected releases are TIBCO Software Inc.'s TIBCO iWay Service Manager: versions 8.0.6 and below.

Affected configurations

Nvd
Node
tibcoiway_service_managerRange<8.0.7
VendorProductVersionCPE
tibcoiway_service_manager*cpe:2.3:a:tibco:iway_service_manager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "TIBCO iWay Service Manager",
    "vendor": "TIBCO Software Inc.",
    "versions": [
      {
        "lessThanOrEqual": "8.0.6",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

22.7%

Related for CVE-2022-30571