CVE-2019-11203Cross-site Scripting in Software INC Tibco Activematrix BPM

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 63.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 24

Description

The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain cross site scripting (XSS) and cross-site request forgery vulnerabilities. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric: versions up

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

🔴Vulnerability Details

2
GHSA
GHSA-qhc9-mv9r-wv6m: The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc2022-05-24
CVEList
TIBCO ActiveMatrix BPM Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities2019-04-24
CVE-2019-11203 — Cross-site Scripting | cvebase