PT-2021-23736 · Tibco Software · Tibco Partnerexpress
Published
2021-11-16
·
Updated
2021-11-19
·
CVE-2021-43048
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIBCO PartnerExpress versions 6.2.1 and below
Description
The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker.
Recommendations
For versions 6.2.1 and below, consider disabling the affected components, specifically the Interior Server and Gateway Server, until a patch or fix is available to prevent potential clickjacking attacks. Restrict network access to minimize the risk of exploitation.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tibco Partnerexpress