CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
55.3%
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users to perform reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions up to and including 5.8.1.fixR, versions 5.9.3, 5.9.4, 5.9.5, and 5.9.6.
Vendor | Product | Version | CPE |
---|---|---|---|
tibco | ebx | * | cpe:2.3:a:tibco:ebx:*:*:*:*:*:*:*:* |
tibco | ebx | 5.8.1 | cpe:2.3:a:tibco:ebx:5.8.1:fixr:*:*:*:*:*:* |
tibco | ebx | 5.9.3 | cpe:2.3:a:tibco:ebx:5.9.3:*:*:*:*:*:*:* |
tibco | ebx | 5.9.4 | cpe:2.3:a:tibco:ebx:5.9.4:*:*:*:*:*:*:* |
tibco | ebx | 5.9.5 | cpe:2.3:a:tibco:ebx:5.9.5:*:*:*:*:*:*:* |
tibco | ebx | 5.9.6 | cpe:2.3:a:tibco:ebx:5.9.6:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
55.3%