CVE-2021-43052: TIBCO FTL Secret Generation Vulnerability
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.7.2 and below, TIBCO FTL - Developer Edition: versions 6.7.2 and below, and TIBCO FTL - Enterprise Edition: versions 6.7.2 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-43052?
CVE-2021-43052 refers to the vulnerability in the Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition.
How severe is CVE-2021-43052?
CVE-2021-43052 is classified as a critical vulnerability with a severity value of 7.5.
How does CVE-2021-43052 affect TIBCO FTL?
CVE-2021-43052 affects TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition versions up to and including 6.7.2.
How can the CVE-2021-43052 vulnerability be exploited?
The CVE-2021-43052 vulnerability allows an attacker to bypass authentication due to a hardcoded secret used in the default realm server of the affected TIBCO FTL components.
Is there a fix for CVE-2021-43052?
To fix CVE-2021-43052, it is recommended to update the affected TIBCO FTL components to a version beyond 6.7.2.