Back

MEDIUM

TIBCO EBX Add-on For Digital Asset Manager Cross-Site Scripting Vulnerabilities

Published Nov 12, 2019

Description

The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2.

Affected products

Remediation

Vendor solution

TIBCO has released updated versions of the affected components which address these issues.

TIBCO EBX Add-ons versions 3.20.13 and below update to version 3.20.14 or higher TIBCO EBX Add-ons versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2 update to version 4.3.0 or higher

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tibco
Published Nov 12, 2019
Updated Sep 16, 2024
Reserved Oct 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner tibco
Published Nov 12, 2019
Updated Sep 16, 2024
Exploited since n/a
EUVD-2019-7743