MEDIUM · 4.3

CVE-2012-0688

Cross-site scripting (XSS) vulnerability in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWork...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
TibcoSilver Fabric Activematrix Service Grid Distribution3.1.3
TibcoActivematrix Service Grid3.0.0
TibcoActivematrix Service Bus3.0.0
TibcoActivematrix Businessworks Service Engine5.9.0
TibcoActivematrix Bpm<= 1.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0688?

CVE-2012-0688 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWork...

How severe is CVE-2012-0688?

CVE-2012-0688 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0688?

Check the references section above for vendor advisories and patch information. Affected products include: Tibco Silver Fabric Activematrix Service Grid Distribution, Tibco Activematrix Service Grid, Tibco Activematrix Service Bus, Tibco Activematrix Businessworks Service Engine, Tibco Activematrix Bpm.