CVE-2021-43055: TIBCO eFTL Token Caching Vulnerability
The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows clients to inherit the permissions of the client that initially connected on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO eFTL - Community Edition: versions 6.7.2 and below, TIBCO eFTL - Developer Edition: versions 6.7.2 and below, and TIBCO eFTL - Enterprise Edition: versions 6.7.2 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-43055?
CVE-2021-43055 is a vulnerability in the eFTL Server component of TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition.
What is the severity of CVE-2021-43055?
CVE-2021-43055 has a severity rating of 8.8 (high).
How does CVE-2021-43055 impact TIBCO eFTL?
CVE-2021-43055 allows clients to inherit the permissions of the client that initially connected on the affected system.
Which versions of TIBCO eFTL are affected by CVE-2021-43055?
CVE-2021-43055 affects TIBCO eFTL Community Edition, Developer Edition, and Enterprise Edition up to and including version 6.7.2.
How can I fix CVE-2021-43055?
To fix CVE-2021-43055, it is recommended to upgrade to a version of TIBCO eFTL that is not affected by the vulnerability.