CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-43048

CVSS 9.8v3.1pub. 2021-11-16upd. 2024-11-21

The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: versions 6.2.1 and below.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Tibco Partnerexpress

    APP
    Tibco
    ≤ 6.2.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2021-43047CRITICAL9.0PL ✓same product

XSS w TIBCO PartnerExpress — Stored i Reflected w komponentach serwera

CVE-2021-43046HIGH7.5same product

The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an eas...

CVE-2020-27147MEDIUM6.5same product

The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretical...

CVE-2025-3115CRITICAL9.4PL ✓same vendor

RCE w Tibco Spotfire — wstrzyknięcie kodu i nievalidowane nazwy plików

CVE-2023-26216CRITICAL9.1PL ✓same vendor

Path Traversal w TIBCO EBX Add-ons — nieautoryzowany upload plików na serwer