CVE-2022-22775
Published on: Not Yet Published
Last Modified on: 05/25/2022 09:42:00 PM UTC
Certain versions of Bpm Enterprise from Tibco contain the following vulnerability:
The Workspace client component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow low privileged attackers with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BPM Enterprise: versions 4.3.1 and below and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric: versions 4.3.1 and below.
- CVE-2022-22775 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO BPM Enterprise version <= 4.3.1
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric version <= 4.3.1
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 3.5 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Advisory | TIBCO Software | web.archive.org text/html Inactive LinkNot Archived |
![]() |
TIBCO Security Advisory: May 17, 2022 - TIBCO ActiveMatrix BPM - CVE-2022-22775 | TIBCO Software | www.tibco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tibco | Bpm Enterprise | All | All | All | All |
Application | Tibco | Bpm Enterprise Distribution For Silver Fabric | All | All | All | All |
- cpe:2.3:a:tibco:bpm_enterprise:*:*:*:*:*:*:*:*:
- cpe:2.3:a:tibco:bpm_enterprise_distribution_for_silver_fabric:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-22775 : The Workspace client component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterpr… twitter.com/i/web/status/1… | 2022-05-17 17:32:30 |
![]() |
CVE-2022-22775 | 2022-05-17 18:39:29 |