Security Advisory regardding TIBCO Administrator

Security Advisory regardding TIBCO Administrator

book

Article ID: KB0108012

calendar_today

Updated On:

Products Versions
TIBCO Runtime Agent for zLinux 5.11.1 and below, 5.10.2 and below
TIBCO Administrator 5.11.1 and below, 5.10.2 and below
TIBCO Administrator - Enterprise Edition For zLinux 5.11.1 and below, 5.10.2 and below

Description

TIBCO Administrator CSV injection vulnerability

  Original release date: April 20, 2021
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains an easily exploitable vulnerability that
  allows a low privileged attacker with network access to execute a persistent
  CSV injection attack from the affected system. A successful attack using this
  vulnerability requires human interaction from a person other than the
  attacker.


Impact

  Successful execution of this vulnerability provides the attacker with the
  ability to exploit the inherent trust an end-user has in the affected system
  and may allow an attacker to:- Infect end users with viruses or malware- Gain
  control over an end-user's computer and execute operating system commands-
  Steal sensitive information- Forge, spoof or modify data that appears to be
  generated by the affected system.

  CVSS v3 Base Score: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L)
 

Issue/Introduction

Security Advisory regardding TIBCO Administrator CSV injection vulnerability

Environment

Products Affected   TIBCO Administrator - Enterprise Edition versions 5.10.2 and below   TIBCO Administrator - Enterprise Edition versions 5.11.0 and 5.11.1   TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver     Fabric versions 5.10.2 and below   TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver     Fabric versions 5.11.0 and 5.11.1   TIBCO Administrator - Enterprise Edition for z/Linux versions 5.10.2 and     below   TIBCO Administrator - Enterprise Edition for z/Linux versions 5.11.0 and     5.11.1   The following component is affected:     * Administration GUI

Resolution


  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO Administrator - Enterprise Edition versions 5.10.2 and below update to
    version 5.10.3 or higher

  TIBCO Administrator - Enterprise Edition versions 5.11.0 and 5.11.1 update
    to version 5.11.2 or higher

  TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver
    Fabric versions 5.10.2 and below update to version 5.10.3 or higher

  TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver
    Fabric versions 5.11.0 and 5.11.1 update to version 5.11.2 or higher

  TIBCO Administrator - Enterprise Edition for z/Linux versions 5.10.2 and
    below update to version 5.10.3 or higher

  TIBCO Administrator - Enterprise Edition for z/Linux versions 5.11.0 and
    5.11.1 update to version 5.11.2 or higher


 

Additional Information

  http://www.tibco.com/services/support/advisories
  CVE-2021-28829