First published: Tue Jan 11 2022(Updated: )
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.7.2 and below, TIBCO FTL - Developer Edition: versions 6.7.2 and below, and TIBCO FTL - Enterprise Edition: versions 6.7.2 and below.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO FTL | <=6.7.2 | |
TIBCO FTL | <=6.7.2 | |
TIBCO FTL | <=6.7.2 |
TIBCO has released updated versions of the affected components which address these issues. TIBCO FTL - Community Edition versions 6.7.2 and below update to version 6.7.3 or later TIBCO FTL - Developer Edition versions 6.7.2 and below update to version 6.7.3 or later TIBCO FTL - Enterprise Edition versions 6.7.2 and below update to version 6.7.3 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43052 refers to the vulnerability in the Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition.
CVE-2021-43052 is classified as a critical vulnerability with a severity value of 7.5.
CVE-2021-43052 affects TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition versions up to and including 6.7.2.
The CVE-2021-43052 vulnerability allows an attacker to bypass authentication due to a hardcoded secret used in the default realm server of the affected TIBCO FTL components.
To fix CVE-2021-43052, it is recommended to update the affected TIBCO FTL components to a version beyond 6.7.2.