Tibco Eftl是美国Tibco公司的一个 Tibco Ftl 和 Tibco Enterprise Message Service™ 的附加组件。将 Tibco Ftl® 消息传递扩展到 Web 浏览器和移动设备等平台。 TIBCO eFTL存在信息泄露漏洞,该漏洞源于允许权限用户利用该漏洞访问令牌生成API,这些API可以访问任何其他通道具有任意权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TIBCO Software Inc. | TIBCO eFTL - Community Edition | unspecified ~ 6.7.2 | - |
|
| TIBCO Software Inc. | TIBCO eFTL - Developer Edition | unspecified ~ 6.7.2 | - |
|
| TIBCO Software Inc. | TIBCO eFTL - Enterprise Edition | unspecified ~ 6.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-43052 | 9.3 CRITICAL | TIBCO FTL Secret Generation Vulnerability |
| CVE-2021-43053 | 8.5 HIGH | TIBCO FTL Secret Exposure Vulnerability |
| CVE-2021-43055 | 5.9 MEDIUM | TIBCO eFTL Token Caching Vulnerability |
No comments yet