Security Advisory regarding TIBCO BusinessConnect Container Edition

Security Advisory regarding TIBCO BusinessConnect Container Edition

book

Article ID: KB0107986

calendar_today

Updated On:

Products Versions
TIBCO BusinessConnect Container Edition 1.1.0

Description

TIBCO BusinessConnect Container Edition username and password leakage

  Original release date: February 15, 2022
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains an easily exploitable vulnerability that
  allows an unauthenticated attacker with network access to obtain the usernames
  and passwords of users of the affected system.

Impact

  In the worst case, if the victim is a privileged administrator, successful
  execution of this vulnerability can result in an attacker gaining full
  administrative access to the affected system.

  CVSS v3 Base Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Issue/Introduction

Security Advisory regarding TIBCO BusinessConnect Container Edition username and password leakage

Environment

Products Affected TIBCO BusinessConnect Container Edition versions 1.1.0 and below The following component is affected: * Database

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO BusinessConnect Container Edition versions 1.1.0 and below update to
    version 1.1.1 or later
 

Additional Information

  https://www.tibco.com/services/support/advisories
  CVE-2021-43049