Improper Certificate Validation in TIBCO products - CVE-2021-35497
Published: October 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper certificate validation in the FTL Server (tibftlserver) and Docker images containing tibftlserver components. A remote authenticated attacker can perform a man-in-the-middle (MitM) attack and gain full administrative access to the affected system.
Affected software
TIBCO ActiveSpaces Enterprise Edition
TIBCO ActiveSpaces Developer Edition
TIBCO eFTL Enterprise Edition
TIBCO eFTL Developer Edition
TIBCO eFTL Community Edition
TIBCO FTL Enterprise Edition
TIBCO FTL Developer Edition
TIBCO FTL Community Edition
How to mitigate CVE-2021-35497
TIBCO ActiveSpaces Enterprise Edition - update to 4.7.0
TIBCO ActiveSpaces Developer Edition - update to 4.7.0
TIBCO eFTL Enterprise Edition - update to 6.7.1
TIBCO eFTL Developer Edition - update to 6.7.1
TIBCO eFTL Community Edition - update to 6.7.1
TIBCO FTL Enterprise Edition - update to 6.7.1
TIBCO FTL Developer Edition - update to 6.7.1
TIBCO FTL Community Edition - update to 6.7.1