Vulnerabilities > Tibco > FTL > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-01-11 CVE-2021-43052 Use of Hard-coded Credentials vulnerability in Tibco FTL
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the affected system.
network
low complexity
tibco CWE-798
5.0
2022-01-11 CVE-2021-43053 Unspecified vulnerability in Tibco FTL
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a difficult to exploit vulnerability that allows an unauthenticated attacker with network access to obtain the cluster secret of another application connected to the realm server.
network
low complexity
tibco
5.0
2021-10-05 CVE-2021-35497 Improper Certificate Validation vulnerability in Tibco Activespaces, Eftl and FTL
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contain a vulnerability that theoretically allows a non-administrative, authenticated FTL user to trick the affected components into creating illegitimate certificates.
network
tibco CWE-295
6.0
2019-08-20 CVE-2019-11209 Unspecified vulnerability in Tibco FTL 6.0.0/6.0.1/6.1.0
The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIBCO FTL Enterprise Edition contains a vulnerability that theoretically fails to properly enforce access controls.
network
low complexity
tibco
6.5
2018-11-06 CVE-2018-12412 Cross-Site Request Forgery (CSRF) vulnerability in Tibco FTL
The realm server (tibrealmserver) component of TIBCO Software Inc.
network
tibco CWE-352
6.8