VYPR
High severity8.8NVD Advisory· Published May 18, 2022· Updated Jun 17, 2026

CVE-2022-22778

CVE-2022-22778

Description

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

Affected products

3
  • cpe:2.3:a:tibco:businessconnect_trading_community_management:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:tibco:businessconnect_trading_community_management:*:*:*:*:*:*:*:*range: <6.1.1
    • (no CPE)range: <=6.1.0
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.