CVE-2021-35498
Published on: 10/13/2021 12:00:00 AM UTC
Last Modified on: 10/20/2021 05:26:00 PM UTC
Certain versions of Ebx from Tibco contain the following vulnerability:
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the legitimate password and it will be accepted as valid. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.123 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, and 5.9.14, TIBCO EBX: versions 6.0.0 and 6.0.1, and TIBCO Product and Service Catalog powered by TIBCO EBX: version 1.0.0.
- CVE-2021-35498 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9.3 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
TIBCO Security Advisory: October 13, 2021 - TIBCO EBX - 2021-35498 | TIBCO Software | www.tibco.com text/html |
![]() |
Advisory | TIBCO Software | web.archive.org text/html Inactive LinkNot Archived |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tibco | Ebx | All | All | All | All |
Application | Tibco | Product And Service Catalog Powered By Tibco Ebx | 1.0.0 | All | All | All |
- cpe:2.3:a:tibco:ebx:*:*:*:*:*:*:*:*:
- cpe:2.3:a:tibco:product_and_service_catalog_powered_by_tibco_ebx:1.0.0:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-35498 : The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and T… twitter.com/i/web/status/1… | 2021-10-13 16:57:58 |