CVE-2021-23272
TIBCO BPM Cross Site Scripting (XSS)
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.6EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
26 ene 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Application Development Clients component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Cross Site Scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BPM Enterprise: versions 4.3.0 and below and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric: versions 4.3.0 and below.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Productos afectados
TIBCO Software Inc. · TIBCO BPM EnterpriseTIBCO Software Inc. · TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →