Skip to content

CVE-2023-26217 | TIBCO EBX Add-ons

The Data Exchange Add-on component of TIBCO Software Inc.’s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permissions and network access to the EBX server to execute arbitrary SQL statements on the affected system. Affected releases are TIBCO Software Inc.’s TIBCO EBX Add-ons: versions 4.5.17 and below, versions 5.6.2 and below, version 6.1.0. .This CVE has a CVSS3.1 score of 8.8 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-26217
CVE StatePUBLISHED
BaseScore8.8
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
VersionNA

References for CVE-2023-26217 :
https://www.tibco.com/services/support/advisories

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)LOW
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)HIGH
Integrity(I)HIGH