CVE Published: 12/01/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2021 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO Data Virtualization Status : PUBLISHED
CVE-2021-35500 Description
The Data Virtualization Server component of TIBCO Software Inc.\'s TIBCO Data Virtualization, TIBCO Data Virtualization, TIBCO Data Virtualization, and TIBCO Data Virtualization for AWS Marketplace contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to download arbitrary files outside of the scope of the user\'s permissions on the affected system. Affected releases are TIBCO Software Inc.\'s TIBCO Data Virtualization: versions 8.3.0 and below, TIBCO Data Virtualization: version 8.4.0, TIBCO Data Virtualization: version 8.5.0, and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.0 and below.
Metrics
CVSS Version: 3.1 |
Base Score: 6.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE-ID: CWE Name: Successful execution of this vulnerability can result in unauthorized read access to all files on the affected system. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)