CVE-2021-28823
Published on: 03/23/2021 12:00:00 AM UTC
Last Modified on: 03/29/2021 07:24:00 PM UTC
Certain versions of Eftl from Tibco contain the following vulnerability:
The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO eFTL - Community Edition: versions 6.5.0 and below, TIBCO eFTL - Developer Edition: versions 6.5.0 and below, and TIBCO eFTL - Enterprise Edition: versions 6.5.0 and below.
- CVE-2021-28823 has been assigned by
sec[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO eFTL - Community Edition version <= 6.5.0
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO eFTL - Developer Edition version <= 6.5.0
- Affected Vendor/Software:
TIBCO Software Inc. - TIBCO eFTL - Enterprise Edition version <= 6.5.0
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 4.6 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Advisory | TIBCO Software | www.tibco.com text/html |
![]() |
Related QID Numbers
- 375730 TIBCO eFTL Windows Platform Installation vulnerability (TIBCO eFTL - 2021-28823)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tibco | Eftl | All | All | All | All |
Application | Tibco | Eftl | All | All | All | All |
Application | Tibco | Eftl | All | All | All | All |
- cpe:2.3:a:tibco:eftl:*:*:*:*:community:*:*:*:
- cpe:2.3:a:tibco:eftl:*:*:*:*:developer:*:*:*:
- cpe:2.3:a:tibco:eftl:*:*:*:*:enterprise:*:*:*:
Discovery Credit
TIBCO would like to extend its appreciation to Will Dormann of CERT/CC for discovery of this vulnerability.