PT-2021-15427 · Tibco Software · Tibco Api Exchange Gateway Distribution For Tibco Silver Fabric+2
Published
2021-03-23
·
Updated
2021-03-26
·
CVE-2021-23274
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIBCO API Exchange Gateway versions 2.3.3 and below
TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric versions 2.3.3 and below
Description
The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker.
Recommendations
For TIBCO API Exchange Gateway versions 2.3.3 and below, update to a version above 2.3.3 to resolve the issue.
For TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric versions 2.3.3 and below, update to a version above 2.3.3 to resolve the issue.
As a temporary workaround, consider restricting access to the Config UI component to minimize the risk of exploitation.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tibco Api Exchange Gateway
Tibco Api Exchange Gateway Distribution For Tibco Silver Fabric
Tibco Silver Fabric