The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.7.2 and below, TIBCO FTL - Developer Edition: versions 6.7.2 and below, and TIBCO FTL - Enterprise Edition: versions 6.7.2 and below.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-30005 The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.7.2 and below, TIBCO FTL - Developer Edition: versions 6.7.2 and below, and TIBCO FTL - Enterprise Edition: versions 6.7.2 and below.
Fixes

Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO FTL - Community Edition versions 6.7.2 and below update to version 6.7.3 or later TIBCO FTL - Developer Edition versions 6.7.2 and below update to version 6.7.3 or later TIBCO FTL - Enterprise Edition versions 6.7.2 and below update to version 6.7.3 or later


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-17T00:10:54.268Z

Reserved: 2021-10-27T00:00:00

Link: CVE-2021-43052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-11T19:15:07.880

Modified: 2024-11-21T06:28:36.153

Link: CVE-2021-43052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses