MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2020-27147

CVSS 6.5v3.1pub. 2020-12-15upd. 2024-11-21

The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login URL for the affected system via a REST API. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: version 6.2.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • Tibco Partnerexpress

    APP
    Tibco
    6.2.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2021-43047CRITICAL9.0PL ✓same product

XSS w TIBCO PartnerExpress — Stored i Reflected w komponentach serwera

CVE-2021-43048CRITICAL9.8PL ✓same product

Clickjacking w TIBCO PartnerExpress — Interior Server i Gateway Server

CVE-2021-43046HIGH7.5same product

The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an eas...

CVE-2025-3115CRITICAL9.4PL ✓same vendor

RCE w Tibco Spotfire — wstrzyknięcie kodu i nievalidowane nazwy plików

CVE-2023-26216CRITICAL9.1PL ✓same vendor

Path Traversal w TIBCO EBX Add-ons — nieautoryzowany upload plików na serwer