Security Advisory regarding TIBCO API Exchange Gateway

Security Advisory regarding TIBCO API Exchange Gateway

book

Article ID: KB0108024

calendar_today

Updated On:

Products Versions
TIBCO API Exchange 2.3.3 and below

Description

 TIBCO API Exchange Gateway Clickjack Vulnerability

 
  Original release date: March 23, 2021
  Last revised: ---
  Source: TIBCO Software Inc.

 
Description

 
  The component listed above contains a vulnerability that theoretically allows
  an unauthenticated attacker with network access to execute a clickjacking
  attack on the affected system. A successful attack using this vulnerability
  does not require human interaction from a person other than the attacker.

 

 
Impact

 
  The impact of this vulnerability includes the theoretical possibility that an
  attacker gains full administrative access to the affected system.

 
  CVSS v3 Base Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

 

Issue/Introduction

Security Advisory regarding TIBCO API Exchange Gateway Clickjack Vulnerability

Environment

Products Affected TIBCO API Exchange Gateway versions 2.3.3 and below TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric versions 2.3.3 and below The following component is affected: * Config UI

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

 
  TIBCO API Exchange Gateway versions 2.3.3 and below update to version 2.4.0
    or higher

 
  TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric versions
    2.3.3 and below update to version 2.4.0 or higher

Additional Information

  http://www.tibco.com/services/support/advisories
  CVE-2021-23274