Use of hard-coded credentials in TIBCO products - CVE-2021-43052
Published: January 12, 2022
Vulnerability identifier: #VU59536
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43052
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain full access to sensitive information.
The vulnerability exists due to presence of hard-coded secret used in the default realm server. A remote unauthenticated attacker can gain full access to communication on an existing eFTL channel on the affected system.
Affected software
TIBCO FTL Community Edition
TIBCO FTL Developer Edition
TIBCO FTL Enterprise Edition
TIBCO FTL Developer Edition
TIBCO FTL Enterprise Edition
How to mitigate CVE-2021-43052
Install updates from vendor's website.
TIBCO FTL Community Edition - update to 6.7.3
TIBCO FTL Developer Edition - update to 6.7.3
TIBCO FTL Enterprise Edition - update to 6.7.3
TIBCO FTL Developer Edition - update to 6.7.3
TIBCO FTL Enterprise Edition - update to 6.7.3