The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the legitimate password and it will be accepted as valid. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.123 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, and 5.9.14, TIBCO EBX: versions 6.0.0 and 6.0.1, and TIBCO Product and Service Catalog powered by TIBCO EBX: version 1.0.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-22139 The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the legitimate password and it will be accepted as valid. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.123 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, and 5.9.14, TIBCO EBX: versions 6.0.0 and 6.0.1, and TIBCO Product and Service Catalog powered by TIBCO EBX: version 1.0.0.
Fixes

Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX versions 5.8.123 and below update to version 5.8.124 or later TIBCO EBX versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, and 5.9.14 update to version 5.9.15 or later TIBCO EBX versions 6.0.0 and 6.0.1 update to version 6.0.2 or later TIBCO Product and Service Catalog powered by TIBCO EBX version 1.0.0 update to version 1.1.0 or later


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-16T17:32:55.642Z

Reserved: 2021-06-24T00:00:00

Link: CVE-2021-35498

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-13T17:15:07.407

Modified: 2024-11-21T06:12:23.287

Link: CVE-2021-35498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.