CVE-2022-41559 Vulnerability Details

  /     /     /  

CVE-2022-41559 Metadata Quick Info

CVE Published: 12/12/2022 | CVE Updated: 16/09/2024 | CVE Year: 2022
Source: tibco | Vendor: TIBCO Software Inc. | Product: TIBCO Nimbus
Status : PUBLISHED

CVE-2022-41559 Description

The Web Client component of TIBCO Software Inc.\'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to exploit an open redirect on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\'s TIBCO Nimbus: version 10.5.0.

Metrics

CVSS Version: 3.1 | Base Score: 9.3 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* CHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Successful execution of these vulnerabilities will result in an attacker being able to execute commands with the privileges of the affected user.
Source: TIBCO Software Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).