HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-43046

CVSS 7.5v3.1pub. 2021-11-16upd. 2024-11-21

The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain session tokens for the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: versions 6.2.1 and below.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Tibco Partnerexpress

    APP
    Tibco
    ≤ 6.2.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2021-43047CRITICAL9.0PL ✓same product

XSS w TIBCO PartnerExpress — Stored i Reflected w komponentach serwera

CVE-2021-43048CRITICAL9.8PL ✓same product

Clickjacking w TIBCO PartnerExpress — Interior Server i Gateway Server

CVE-2020-27147MEDIUM6.5same product

The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretical...

CVE-2025-3115CRITICAL9.4PL ✓same vendor

RCE w Tibco Spotfire — wstrzyknięcie kodu i nievalidowane nazwy plików

CVE-2023-26216CRITICAL9.1PL ✓same vendor

Path Traversal w TIBCO EBX Add-ons — nieautoryzowany upload plików na serwer