Stored XSS Vulnerability in TIBCO ActiveMatrix Administrator
CVE-2025-2261

7HIGH

Key Information:

Vendor

Tibco

Vendor
CVE Published:
21 May 2025

What is CVE-2025-2261?

The vulnerability in TIBCO ActiveMatrix Administrator allows attackers to inject malicious data into the application. This payload can execute within the user's browser, leveraging the web application’s privileges and potentially compromising sensitive user information. It highlights the critical need for robust input validation to safeguard against such threats.

Affected Version(s)

TIBCO BPM Enterprise 4.3 < 4

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2261 : Stored XSS Vulnerability in TIBCO ActiveMatrix Administrator