Improper Authentication in TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX - CVE-2021-35498
Published: October 14, 2021
Vulnerability identifier: #VU57347
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35498
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to insecure login mechanism in the TIBCO EBX Web Server component. A remote attacker can enter a password other than the legitimate password and it will be accepted as valid.
Affected software
TIBCO EBX
TIBCO Product and Service Catalog powered by TIBCO EBX
TIBCO Product and Service Catalog powered by TIBCO EBX
How to mitigate CVE-2021-35498
Install updates from vendor's website.
TIBCO EBX - addressed in versions 5.8.124, 5.9.15, 6.0.2
TIBCO Product and Service Catalog powered by TIBCO EBX - update to 1.1.0
TIBCO Product and Service Catalog powered by TIBCO EBX - update to 1.1.0