CVE-2021-35497
TIBCO FTL unvalidated SAN in client certificates
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contain a vulnerability that theoretically allows a non-administrative, authenticated FTL user to trick the affected components into creating illegitimate certificates. These maliciously generated certificates can be used to enable man-in-the-middle attacks or to escalate privileges so that the malicious user has administrative privileges. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.6.1, and 4.6.2, TIBCO ActiveSpaces - Developer Edition: versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.6.1, and 4.6.2, TIBCO ActiveSpaces - Enterprise Edition: versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.6.1, and 4.6.2, TIBCO FTL - Community Edition: versions 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1, and 6.7.0, TIBCO FTL - Developer Edition: versions 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1, and 6.7.0, TIBCO FTL - Enterprise Edition: versions 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1, and 6.7.0, TIBCO eFTL - Community Edition: versions 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1, and 6.7.0, TIBCO eFTL - Developer Edition: versions 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1, and 6.7.0, and TIBCO eFTL - Enterprise Edition: versions 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1, and 6.7.0.
El servidor FTL (tibftlserver) y las imágenes Docker que contienen los componentes tibftlserver de TIBCO Software Inc. TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, y TIBCO eFTL - Enterprise Edition. contienen una vulnerabilidad que teóricamente permite a un usuario de FTL no administrativo y autenticado engañar a los componentes afectados para que creen certificados ilegítimos. Estos certificados generados de forma maliciosa pueden ser usados para habilitar ataques de tipo man-in-the-middle o para escalar privilegios de forma que el usuario malicioso tenga privilegios administrativos. Las versiones afectadas son TIBCO ActiveSpaces - Community Edition de TIBCO Software Inc.: versiones 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.6.1 y 4.6.2, TIBCO ActiveSpaces - Developer Edition: versiones 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.6.1 y 4.6. 2, TIBCO ActiveSpaces - Enterprise Edition: versiones 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.6.1 y 4.6.2, TIBCO FTL - Community Edition: versiones 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1 y 6.7.0, TIBCO FTL - Developer Edition: versiones 6. 2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1 y 6.7.0, TIBCO FTL - Enterprise Edition: versiones 6.2.0, 6.3.0, 6. 3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1 y 6.7.0, TIBCO eFTL - Community Edition: versiones 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5. 0, 6.6.0, 6.6.1 y 6.7.0, TIBCO eFTL - Developer Edition: versiones 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6. 1 y 6.7.0, y TIBCO eFTL - Enterprise Edition: versiones 6.2.0, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.6.0, 6.6.1 y 6.7.0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-24 CVE Reserved
- 2021-10-05 CVE Published
- 2023-04-28 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.3.0 Search vendor "Tibco" for product "Activespaces" and version "4.3.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.3.0 Search vendor "Tibco" for product "Activespaces" and version "4.3.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.3.0 Search vendor "Tibco" for product "Activespaces" and version "4.3.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.4.0 Search vendor "Tibco" for product "Activespaces" and version "4.4.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.4.0 Search vendor "Tibco" for product "Activespaces" and version "4.4.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.4.0 Search vendor "Tibco" for product "Activespaces" and version "4.4.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.5.0 Search vendor "Tibco" for product "Activespaces" and version "4.5.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.5.0 Search vendor "Tibco" for product "Activespaces" and version "4.5.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.5.0 Search vendor "Tibco" for product "Activespaces" and version "4.5.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.0 Search vendor "Tibco" for product "Activespaces" and version "4.6.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.0 Search vendor "Tibco" for product "Activespaces" and version "4.6.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.0 Search vendor "Tibco" for product "Activespaces" and version "4.6.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.1 Search vendor "Tibco" for product "Activespaces" and version "4.6.1" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.1 Search vendor "Tibco" for product "Activespaces" and version "4.6.1" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.1 Search vendor "Tibco" for product "Activespaces" and version "4.6.1" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.2 Search vendor "Tibco" for product "Activespaces" and version "4.6.2" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.2 Search vendor "Tibco" for product "Activespaces" and version "4.6.2" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Activespaces Search vendor "Tibco" for product "Activespaces" | 4.6.2 Search vendor "Tibco" for product "Activespaces" and version "4.6.2" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.2.0 Search vendor "Tibco" for product "Eftl" and version "6.2.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.2.0 Search vendor "Tibco" for product "Eftl" and version "6.2.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.2.0 Search vendor "Tibco" for product "Eftl" and version "6.2.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.3.0 Search vendor "Tibco" for product "Eftl" and version "6.3.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.3.0 Search vendor "Tibco" for product "Eftl" and version "6.3.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.3.0 Search vendor "Tibco" for product "Eftl" and version "6.3.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.3.1 Search vendor "Tibco" for product "Eftl" and version "6.3.1" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.3.1 Search vendor "Tibco" for product "Eftl" and version "6.3.1" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.3.1 Search vendor "Tibco" for product "Eftl" and version "6.3.1" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.4.0 Search vendor "Tibco" for product "Eftl" and version "6.4.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.4.0 Search vendor "Tibco" for product "Eftl" and version "6.4.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.4.0 Search vendor "Tibco" for product "Eftl" and version "6.4.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.5.0 Search vendor "Tibco" for product "Eftl" and version "6.5.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.5.0 Search vendor "Tibco" for product "Eftl" and version "6.5.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.5.0 Search vendor "Tibco" for product "Eftl" and version "6.5.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.6.0 Search vendor "Tibco" for product "Eftl" and version "6.6.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.6.0 Search vendor "Tibco" for product "Eftl" and version "6.6.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.6.0 Search vendor "Tibco" for product "Eftl" and version "6.6.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.6.1 Search vendor "Tibco" for product "Eftl" and version "6.6.1" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.6.1 Search vendor "Tibco" for product "Eftl" and version "6.6.1" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.6.1 Search vendor "Tibco" for product "Eftl" and version "6.6.1" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.7.0 Search vendor "Tibco" for product "Eftl" and version "6.7.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.7.0 Search vendor "Tibco" for product "Eftl" and version "6.7.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Eftl Search vendor "Tibco" for product "Eftl" | 6.7.0 Search vendor "Tibco" for product "Eftl" and version "6.7.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.2.0 Search vendor "Tibco" for product "Ftl" and version "6.2.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.2.0 Search vendor "Tibco" for product "Ftl" and version "6.2.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.2.0 Search vendor "Tibco" for product "Ftl" and version "6.2.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.3.0 Search vendor "Tibco" for product "Ftl" and version "6.3.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.3.0 Search vendor "Tibco" for product "Ftl" and version "6.3.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.3.0 Search vendor "Tibco" for product "Ftl" and version "6.3.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.3.1 Search vendor "Tibco" for product "Ftl" and version "6.3.1" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.3.1 Search vendor "Tibco" for product "Ftl" and version "6.3.1" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.3.1 Search vendor "Tibco" for product "Ftl" and version "6.3.1" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.4.0 Search vendor "Tibco" for product "Ftl" and version "6.4.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.4.0 Search vendor "Tibco" for product "Ftl" and version "6.4.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.4.0 Search vendor "Tibco" for product "Ftl" and version "6.4.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.5.0 Search vendor "Tibco" for product "Ftl" and version "6.5.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.5.0 Search vendor "Tibco" for product "Ftl" and version "6.5.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.5.0 Search vendor "Tibco" for product "Ftl" and version "6.5.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.6.0 Search vendor "Tibco" for product "Ftl" and version "6.6.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.6.0 Search vendor "Tibco" for product "Ftl" and version "6.6.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.6.0 Search vendor "Tibco" for product "Ftl" and version "6.6.0" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.6.1 Search vendor "Tibco" for product "Ftl" and version "6.6.1" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.6.1 Search vendor "Tibco" for product "Ftl" and version "6.6.1" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.6.1 Search vendor "Tibco" for product "Ftl" and version "6.6.1" | enterprise |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.7.0 Search vendor "Tibco" for product "Ftl" and version "6.7.0" | community |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.7.0 Search vendor "Tibco" for product "Ftl" and version "6.7.0" | developer |
Affected
| ||||||
Tibco Search vendor "Tibco" | Ftl Search vendor "Tibco" for product "Ftl" | 6.7.0 Search vendor "Tibco" for product "Ftl" and version "6.7.0" | enterprise |
Affected
|