CVE-2025-2261 - CVE House
Back to Database
Status published High CVE-2025-2261

TIBCO BPM Enterprise XSS Vulnerability

Vulnerability Description

Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2261

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

TIBCO Software Inc

View all reports →

Affected Software

TIBCO BPM Enterprise
Vulnerable Versions:
4.3

Timeline

Official Publish: May 21st, 2025
Last Modified: May 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)