CVE-2021-28827: TIBCO Administrator Stored Cross Site Scripting vulnerability
The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition for z/Linux, TIBCO Administrator - Enterprise Edition for z/Linux, TIBCO Runtime Agent, TIBCO Runtime Agent, TIBCO Runtime Agent for z/Linux, and TIBCO Runtime Agent for z/Linux contains an easily exploitable vulnerability that allows an unauthenticated attacker to social engineer a legitimate user with network access to execute a Stored XSS attack targeting the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition: versions 5.10.2 and below, TIBCO Administrator - Enterprise Edition: versions 5.11.0 and 5.11.1, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric: versions 5.10.2 and below, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric: versions 5.11.0 and 5.11.1, TIBCO Administrator - Enterprise Edition for z/Linux: versions 5.10.2 and below, TIBCO Administrator - Enterprise Edition for z/Linux: versions 5.11.0 and 5.11.1, TIBCO Runtime Agent: versions 5.10.2 and below, TIBCO Runtime Agent: versions 5.11.0 and 5.11.1, TIBCO Runtime Agent for z/Linux: versions 5.10.2 and below, and TIBCO Runtime Agent for z/Linux: versions 5.11.0 and 5.11.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-28827?
CVE-2021-28827 is a vulnerability in TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition that allows remote attackers to execute arbitrary code.
How severe is CVE-2021-28827?
CVE-2021-28827 has a severity score of 9.6 (critical).
Which software versions are affected by CVE-2021-28827?
TIBCO Administrator versions up to and including 5.10.2 and TIBCO Runtime Agent versions up to and including 5.10.2 are affected by CVE-2021-28827.
How can I fix CVE-2021-28827?
To fix CVE-2021-28827, it is recommended to upgrade to a version of TIBCO Administrator and TIBCO Runtime Agent that is higher than 5.10.2.
Where can I find more information about CVE-2021-28827?
You can find more information about CVE-2021-28827 on the TIBCO Software Inc. support website and the TIBCO security advisory page.