CVE-2017-16789
Summary
| CVE | CVE-2017-16789 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-11 02:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via the users management panel of the web interface. |
Risk And Classification
Primary CVSS: v3.0 4.8 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.001790000 probability, percentile 0.391190000 (date 2026-05-17)
Problem Types: CWE-79 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 4.8 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Integrationmatters | Njams | 3 | All | All | All |
| Application | Tibco | Businessworks Process Monitor | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.integrationmatters.com/cms/upload/Resources/nJAMS_SecurityUpdate_CVE-2017-16789.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.integrationmatters.com | |
| CVE-2017-16789: XSS Vulnerability Details ===================================== - Pastebin.com | af854a3a-2127-422b-91ae-364da2661108 | pastebin.com | Third Party Advisory |
| www.on-x.com/sites/default/files/on-x_-_security_advisory_-_njams3_-_cve-2... | af854a3a-2127-422b-91ae-364da2661108 | www.on-x.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Integration Matters | 2018-01-18 | Hendrik Siegeln | The reported vulnerability was fixed in version 3.2.0 Hotfix 3 of the affected product. The new version was made available on June-28-2017 to all customers.<br /> We encourage all customers to upgrade to at least the mentioned hot fix level. Reference web sites: <br /> https://www.integrationmatters.com/downloads/software/<br /> https://support.integrationmatters.com |
There are currently no legacy QID mappings associated with this CVE.