First published: Tue Mar 23 2021(Updated: )
The FTL Server (tibftlserver), FTL C API, FTL Golang API, FTL Java API, and FTL .Net API components of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from the affected component searching for run-time artifacts outside of the installation hierarchy. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.5.0 and below, TIBCO FTL - Developer Edition: versions 6.5.0 and below, and TIBCO FTL - Enterprise Edition: versions 6.5.0 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO FTL | <6.6.0 | |
TIBCO FTL | <6.6.0 | |
TIBCO FTL | <6.6.0 | |
Microsoft Windows |
TIBCO has released updated versions of the affected components which address these issues. TIBCO FTL - Community Edition versions 6.5.0 and below update to version 6.6.0 or higher TIBCO FTL - Developer Edition versions 6.5.0 and below update to version 6.6.0 or higher TIBCO FTL - Enterprise Edition versions 6.5.0 and below update to version 6.6.0 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-28820.
CVE-2021-28820 has a severity rating of 7.8, which is considered high.
CVE-2021-28820 affects TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition up to version 6.6.0.
CVE-2021-28820 is a vulnerability in the FTL Server (tibftlserver), FTL C API, FTL Golang API, FTL Java API, and FTL .Net API components of TIBCO Software Inc.'s TIBCO FTL products, which could potentially be exploited by a low privileged attacker.
You can find more information about CVE-2021-28820 in the advisory published by TIBCO Software Inc.