Security Advisory regarding TIBCO Administrator

Security Advisory regarding TIBCO Administrator

book

Article ID: KB0108013

calendar_today

Updated On:

Products Versions
TIBCO Runtime Agent (TRA) 5.11.1 and below, 5.10.2 and below
TIBCO Administrator 5.11.1 and below, 5.10.2 and below
TIBCO Administrator - Enterprise Edition For zLinux 5.11.1 and below, 5.10.2 and below

Description

TIBCO Administrator SQL injection vulnerability

  Original release date: April 20, 2021
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains an easily exploitable vulnerability that
  allows a low privileged attacker with network access to execute a SQL
  injection attack on the affected system.


Impact

  Successful execution of this vulnerability may result in unauthorized read,
  update, insert or delete access to TIBCO Administrator data on the affected
  system.

  CVSS v3 Base Score: 7.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L)

 

Environment

Products Affected   TIBCO Administrator - Enterprise Edition versions 5.10.2 and below   TIBCO Administrator - Enterprise Edition versions 5.11.0 and 5.11.1   TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver     Fabric versions 5.10.2 and below   TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver     Fabric versions 5.11.0 and 5.11.1   TIBCO Administrator - Enterprise Edition for z/Linux versions 5.10.2 and     below   TIBCO Administrator - Enterprise Edition for z/Linux versions 5.11.0 and     5.11.1   The following component is affected:     * Administration GUI

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO Administrator - Enterprise Edition versions 5.10.2 and below update to
    version 5.10.3 or higher

  TIBCO Administrator - Enterprise Edition versions 5.11.0 and 5.11.1 update
    to version 5.11.2 or higher

  TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver
    Fabric versions 5.10.2 and below update to version 5.10.3 or higher

  TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver
    Fabric versions 5.11.0 and 5.11.1 update to version 5.11.2 or higher

  TIBCO Administrator - Enterprise Edition for z/Linux versions 5.10.2 and
    below update to version 5.10.3 or higher

  TIBCO Administrator - Enterprise Edition for z/Linux versions 5.11.0 and
    5.11.1 update to version 5.11.2 or higher

Issue/Introduction

Security Advisory regarding TIBCO Administrator SQL injection vulnerability

Additional Information

  http://www.tibco.com/services/support/advisories
  CVE-2021-28828