PT-2021-15427 · Tibco Software · Tibco Api Exchange Gateway Distribution For Tibco Silver Fabric+2

Published

2021-03-23

·

Updated

2021-03-26

·

CVE-2021-23274

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TIBCO API Exchange Gateway versions 2.3.3 and below TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric versions 2.3.3 and below
Description The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker.
Recommendations For TIBCO API Exchange Gateway versions 2.3.3 and below, update to a version above 2.3.3 to resolve the issue. For TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric versions 2.3.3 and below, update to a version above 2.3.3 to resolve the issue. As a temporary workaround, consider restricting access to the Config UI component to minimize the risk of exploitation.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23274

Affected Products

Tibco Api Exchange Gateway
Tibco Api Exchange Gateway Distribution For Tibco Silver Fabric
Tibco Silver Fabric