TIBCO Administrator - Enterprise Edition For zLinux
5.11.1 and below, 5.10.2 and below
Description
TIBCO Administrator CSV injection vulnerability
Original release date: April 20, 2021 Last revised: --- Source: TIBCO Software Inc.
Description
The component listed above contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a persistent CSV injection attack from the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker.
Impact
Successful execution of this vulnerability provides the attacker with the ability to exploit the inherent trust an end-user has in the affected system and may allow an attacker to:- Infect end users with viruses or malware- Gain control over an end-user's computer and execute operating system commands- Steal sensitive information- Forge, spoof or modify data that appears to be generated by the affected system.
CVSS v3 Base Score: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L)
Environment
Products Affected
TIBCO Administrator - Enterprise Edition versions 5.10.2 and below
TIBCO Administrator - Enterprise Edition versions 5.11.0 and 5.11.1
TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver
Fabric versions 5.10.2 and below
TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver
Fabric versions 5.11.0 and 5.11.1
TIBCO Administrator - Enterprise Edition for z/Linux versions 5.10.2 and
below
TIBCO Administrator - Enterprise Edition for z/Linux versions 5.11.0 and
5.11.1
The following component is affected:
* Administration GUI
Resolution
TIBCO has released updated versions of the affected systems which address this issue:
TIBCO Administrator - Enterprise Edition versions 5.10.2 and below update to version 5.10.3 or higher
TIBCO Administrator - Enterprise Edition versions 5.11.0 and 5.11.1 update to version 5.11.2 or higher
TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric versions 5.10.2 and below update to version 5.10.3 or higher
TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric versions 5.11.0 and 5.11.1 update to version 5.11.2 or higher
TIBCO Administrator - Enterprise Edition for z/Linux versions 5.10.2 and below update to version 5.10.3 or higher
TIBCO Administrator - Enterprise Edition for z/Linux versions 5.11.0 and 5.11.1 update to version 5.11.2 or higher