The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login URL for the affected system via a REST API. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: version 6.2.0.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NTibco Partnerexpress
APPTibco6.2.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Auth Bypass
Powiązane podatności
CVE-2021-43047CRITICAL9.0PL ✓ten sam produkt
XSS w TIBCO PartnerExpress — Stored i Reflected w komponentach serwera
CVE-2021-43048CRITICAL9.8PL ✓ten sam produkt
Clickjacking w TIBCO PartnerExpress — Interior Server i Gateway Server
CVE-2021-43046HIGH7.5ten sam produkt
The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an eas...
CVE-2025-3115CRITICAL9.4PL ✓ten sam vendor
RCE w Tibco Spotfire — wstrzyknięcie kodu i nievalidowane nazwy plików
CVE-2023-26216CRITICAL9.1PL ✓ten sam vendor
Path Traversal w TIBCO EBX Add-ons — nieautoryzowany upload plików na serwer