Vulnerabilities > Tibco > Partnerexpress > 6.1.0

DATE CVE VULNERABILITY TITLE RISK
2021-11-16 CVE-2021-43046 Unspecified vulnerability in Tibco Partnerexpress
The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain session tokens for the affected system.
network
tibco
critical
9.3
2021-11-16 CVE-2021-43047 Cross-site Scripting vulnerability in Tibco Partnerexpress
The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system.
network
tibco CWE-79
8.5
2021-11-16 CVE-2021-43048 Improper Restriction of Rendered UI Layers or Frames vulnerability in Tibco Partnerexpress
The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system.
network
low complexity
tibco CWE-1021
critical
10.0