CVE-2022-22777
Published on: Not Yet Published
Last Modified on: 05/31/2022 01:19:00 PM UTC
Certain versions of Businessconnect Trading Community Management from Tibco contain the following vulnerability:
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow an unauthenticated attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.
- CVE-2022-22777 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO BusinessConnect Trading Community Management version <= 6.1.0
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Advisory | TIBCO Software | web.archive.org text/html Inactive LinkNot Archived |
![]() |
TIBCO Security Advisory: May 18, 2022 - TIBCO BusinessConnect Trading Community Management - CVE-2022-22777 | TIBCO Software | www.tibco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tibco | Businessconnect Trading Community Management | All | All | All | All |
- cpe:2.3:a:tibco:businessconnect_trading_community_management:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
It's interesting that GitHub didn't mark our repositories as vulnerable due to CVE-2022-22577 and CVE-2022-22777, a… twitter.com/i/web/status/1… | 2022-04-27 03:57:48 |
![]() |
CVE-2022-22777 : The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Manageme… twitter.com/i/web/status/1… | 2022-05-18 17:08:02 |
![]() |
CVE-2022-22777 | 2022-05-18 17:38:31 |