CVE-2021-35500
TIBCO Data Virtualization Arbitrary File Download vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization, TIBCO Data Virtualization, TIBCO Data Virtualization, and TIBCO Data Virtualization for AWS Marketplace contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to download arbitrary files outside of the scope of the user's permissions on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 8.3.0 and below, TIBCO Data Virtualization: version 8.4.0, TIBCO Data Virtualization: version 8.5.0, and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.0 and below.
El componente Data Virtualization Server de TIBCO Software Inc.'s TIBCO Data Virtualization, TIBCO Data Virtualization, TIBCO Data Virtualization, y TIBCO Data Virtualization for AWS Marketplace contiene una vulnerabilidad difícil de explotar que permite a un atacante con pocos privilegios y acceso local descargar archivos arbitrarios fuera del alcance de los permisos del usuario en el sistema afectado. Las versiones afectadas son TIBCO Data Virtualization de TIBCO Software Inc.: versiones 8.3.0 y anteriores, TIBCO Data Virtualization: versión 8.4.0, TIBCO Data Virtualization: versión 8.5.0, y TIBCO Data Virtualization para AWS Marketplace: versiones 8.5.0 y anteriores
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-24 CVE Reserved
- 2022-01-12 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Data Virtualization Search vendor "Tibco" for product "Data Virtualization" | <= 8.3.0 Search vendor "Tibco" for product "Data Virtualization" and version " <= 8.3.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Data Virtualization Search vendor "Tibco" for product "Data Virtualization" | 8.4.0 Search vendor "Tibco" for product "Data Virtualization" and version "8.4.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Data Virtualization Search vendor "Tibco" for product "Data Virtualization" | 8.5.0 Search vendor "Tibco" for product "Data Virtualization" and version "8.5.0" | - |
Affected
| ||||||
Tibco Search vendor "Tibco" | Data Virtualization For Aws Marketplace Search vendor "Tibco" for product "Data Virtualization For Aws Marketplace" | <= 8.5.0 Search vendor "Tibco" for product "Data Virtualization For Aws Marketplace" and version " <= 8.5.0" | - |
Affected
|