CVE-2021-28823: TIBCO eFTL Windows Platform Installation vulnerability
The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO eFTL - Community Edition: versions 6.5.0 and below, TIBCO eFTL - Developer Edition: versions 6.5.0 and below, and TIBCO eFTL - Enterprise Edition: versions 6.5.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this TIBCO eFTL vulnerability?
The vulnerability ID for this TIBCO eFTL vulnerability is CVE-2021-28823.
What is the severity rating of CVE-2021-28823?
CVE-2021-28823 has a severity rating of 7.8 (High).
Which versions of TIBCO eFTL are affected by CVE-2021-28823?
Versions up to and excluding 6.6.0 of TIBCO eFTL, including Community Edition, Developer Edition, and Enterprise Edition, are affected by CVE-2021-28823.
What is the description of CVE-2021-28823?
CVE-2021-28823 is a vulnerability in the Windows Installation component of TIBCO eFTL that allows a low privileged attacker with local access on some versions of Windows operating systems to potentially exploit the system.
Where can I find more information about CVE-2021-28823?
You can find more information about CVE-2021-28823 on the TIBCO website at http://www.tibco.com/services/support/advisories.