PT-2021-23734 · Tibco · Tibco Partnerexpress
Published
2021-11-16
·
Updated
2021-11-19
·
CVE-2021-43046
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIBCO PartnerExpress versions 6.2.1 and below
Description
The vulnerability in TIBCO PartnerExpress allows an unauthenticated attacker with network access to obtain session tokens for the affected system. This can be achieved through an easily exploitable vulnerability. A successful attack requires human interaction from a person other than the attacker.
Recommendations
For versions 6.2.1 and below, update to a version above 6.2.1 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tibco Partnerexpress