CVE Vulnerabilities

CVE-2021-35500

Published: Jan 12, 2022 | Modified: Jan 19, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Data Virtualization Server component of TIBCO Software Inc.s TIBCO Data Virtualization, TIBCO Data Virtualization, TIBCO Data Virtualization, and TIBCO Data Virtualization for AWS Marketplace contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to download arbitrary files outside of the scope of the users permissions on the affected system. Affected releases are TIBCO Software Inc.s TIBCO Data Virtualization: versions 8.3.0 and below, TIBCO Data Virtualization: version 8.4.0, TIBCO Data Virtualization: version 8.5.0, and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.0 and below.

Affected Software

Name Vendor Start Version End Version
Data_virtualization Tibco * 8.3.0 (including)
Data_virtualization Tibco 8.4.0 (including) 8.4.0 (including)
Data_virtualization Tibco 8.5.0 (including) 8.5.0 (including)
Data_virtualization_for_aws_marketplace Tibco * 8.5.0 (including)

References