SB2022081040 - Multiple vulnerabilities in TIBCO FTL and eFTL



SB2022081040 - Multiple vulnerabilities in TIBCO FTL and eFTL

Published: August 10, 2022

Security Bulletin ID SB2022081040
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2022-30573)

The vulnerability allows a remote user on the local network to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in the ftlserver component, which leads to security restrictions bypass and privilege escalation.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2022-30574)

The vulnerability allows a remote user on the local network to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in the ftlserver component, which leads to security restrictions bypass and privilege escalation.


Remediation

Install update from vendor's website.