CVE Published: 15/02/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO BusinessConnect Container Edition Status : PUBLISHED
CVE-2021-43049 Description
The Database component of TIBCO Software Inc.\'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain the usernames and passwords of users of the affected system. Affected releases are TIBCO Software Inc.\'s TIBCO BusinessConnect Container Edition: versions 1.1.0 and below.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE Name: In the worst case, if the victim is a privileged administrator, successful execution of this vulnerability can result in an attacker gaining full administrative access to the affected system. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)