Lucene search

K
nvd[email protected]NVD:CVE-2022-30576
HistoryAug 16, 2022 - 6:15 p.m.

CVE-2022-30576

2022-08-1618:15:08
CWE-79
web.nvd.nist.gov
2
tibco
xss
web console
vulnerability
stored cross site scripting
network access
human interaction
low privileged attacker
cve-2022-30576
tibco data science
statistica
estore edition
trial

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.7%

The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Data Science - Workbench: versions 14.0.0 and below, TIBCO Statistica: versions 14.0.0 and below, TIBCO Statistica - Estore Edition: versions 14.0.0 and below, and TIBCO Statistica Trial: versions 14.0.0 and below.

Affected configurations

Nvd
Node
tibcodata_science_-_workbenchRange<14.0.1
OR
tibcostatisticaRange<14.0.1-
OR
tibcostatisticaRange<14.0.1estore
OR
tibcostatisticaRange<14.0.1trial
VendorProductVersionCPE
tibcodata_science_-_workbench*cpe:2.3:a:tibco:data_science_-_workbench:*:*:*:*:*:*:*:*
tibcostatistica*cpe:2.3:a:tibco:statistica:*:*:*:*:-:*:*:*
tibcostatistica*cpe:2.3:a:tibco:statistica:*:*:*:*:estore:*:*:*
tibcostatistica*cpe:2.3:a:tibco:statistica:*:*:*:*:trial:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.7%

Related for NVD:CVE-2022-30576