CVE-2021-43049: TIBCO BusinessConnect Container Edition username and password leakage
The Database component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain the usernames and passwords of users of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition: versions 1.1.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-43049?
CVE-2021-43049 is a vulnerability in the Database component of TIBCO BusinessConnect Container Edition that allows an unauthenticated attacker to obtain usernames and passwords.
How severe is CVE-2021-43049?
CVE-2021-43049 is considered a critical vulnerability with a severity score of 9.8.
Which software versions are affected by CVE-2021-43049?
Versions of TIBCO BusinessConnect Container Edition up to and excluding version 1.1.1 are affected by CVE-2021-43049.
How can an attacker exploit CVE-2021-43049?
An unauthenticated attacker with network access can exploit CVE-2021-43049 to obtain the usernames and passwords of users of the affected system.
Where can I find more information about CVE-2021-43049?
You can find more information about CVE-2021-43049 in the TIBCO Security Advisory and Support Advisories provided by TIBCO Software Inc.