CVE-2021-43055
TIBCO eFTL Token Caching Vulnerability
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Jan 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows clients to inherit the permissions of the client that initially connected on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO eFTL - Community Edition: versions 6.7.2 and below, TIBCO eFTL - Developer Edition: versions 6.7.2 and below, and TIBCO eFTL - Enterprise Edition: versions 6.7.2 and below.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
TIBCO Software Inc. · TIBCO eFTL - Community EditionTIBCO Software Inc. · TIBCO eFTL - Developer EditionTIBCO Software Inc. · TIBCO eFTL - Enterprise EditionWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →