
CVE-2022-30572 – TIBCO iWay Service Manager Directory Traversal Vulnerability
https://notcve.org/view.php?id=CVE-2022-30572
02 Aug 2022 — The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploitable Directory Traversal vulnerability that allows a low privileged attacker with network access to read arbitrary resources on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO iWay Service Manager: versions 8.0.6 and below. El componente iWay Service Manager Console de TIBCO Software Inc.' • https://www.tibco.com/services/support/advisories • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2022-30571 – TIBCO iWay Service Manager Reflected Cross Site Scripting (XSS) Vulnerability
https://notcve.org/view.php?id=CVE-2022-30571
02 Aug 2022 — The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO iWay Service Manager: versions 8.0.6 and below. El componente iWay Service Manager Console de TIBCO Software Inc. contiene vulnerabilidades de tipo Cr... • https://www.tibco.com/services/support/advisories • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •