Skip to main content

Vendor archive

tibco CVEs

Beta · best-effort

225 CVEs tagged to vendor tibco42 Critical, 100 High, 82 Medium, 1 Low, 0 Unrated.

CVE-2026-3207

Published Mar 17, 2026

Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3115

Published Apr 9, 2025

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of fil…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2024-4576

Published Jun 13, 2024

The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system config…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26222

Published Nov 14, 2023

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allow…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26218

Published Sep 29, 2023

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacke…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26217

Published Jul 19, 2023

The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permission…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26216

Published May 25, 2023

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26215

Published May 25, 2023

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application access to read system files that…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-29268

Published Apr 26, 2023

The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26214

Published Feb 22, 2023

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low p…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41567

Published Feb 22, 2023

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network acc…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41566

Published Feb 22, 2023

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute s…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41563

Published Dec 13, 2022

The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-41562

Published Dec 13, 2022

The HTML escaping component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Se…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41561

Published Dec 13, 2022

The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReport…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-41560

Published Dec 6, 2022

The Statement Set Upload via the Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows a low privileged attacker with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41559

Published Dec 6, 2022

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to exploit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-30578

Published Sep 21, 2022

The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execu…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30577

Published Sep 21, 2022

The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Store…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 225 CVEsPage 1 of 9