Improper access control in TIBCO products - CVE-2021-28824

 

Improper access control in TIBCO products - CVE-2021-28824

Published: March 24, 2021


Vulnerability identifier: #VU51682
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28824
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions on certain files and/or folders in the Windows Installation component. A local user can insert malicious software and gain full access to the Windows operating system.


Affected software

TIBCO ActiveSpaces Enterprise Edition
TIBCO ActiveSpaces Community Edition
TIBCO ActiveSpaces Developer Edition

How to mitigate CVE-2021-28824

Install updates from vendor's website.

TIBCO ActiveSpaces Enterprise Edition - update to 4.6.0
TIBCO ActiveSpaces Community Edition - update to 4.6.0
TIBCO ActiveSpaces Developer Edition - update to 4.6.0

External References

Related Security Bulletins