QID 375730

Date Published: 2021-08-25

QID 375730: TIBCO eFTL Windows Platform Installation vulnerability (TIBCO eFTL - 2021-28823)

TIBCO Software Inc.'s TIBCO eFTL contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software.

Affected Version:
TIBCO eFTL - Community Edition versions 6.5.0 and below

QID Detection Logic(Authenticated)
This QID checks for the vulnerable version of TIBCO eFTL on the system

Successful exploitation of this vulnerability can allow attackers to execute the malicious software inserted by the attacker with the elevated privileges of the component.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    The vendor has released updates to fix the vulnerabilities. Please refer to TIBCO eFTL - 2021-28823 for details.

    CVEs related to QID 375730

    Software Advisories
    Advisory ID Software Component Link
    TIBCO eFTL - 2021-28823 URL Logo www.tibco.com/support/advisories/2021/03/tibco-security-advisory-march-23-2021-tibco-eftl-2021-28823