{ "schema_version": "1.4.0", "id": "GHSA-rr3v-gc7h-j55r", "modified": "2022-01-20T00:02:41Z", "published": "2022-01-12T00:01:17Z", "aliases": [ "CVE-2021-43052" ], "details": "The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.7.2 and below, TIBCO FTL - Developer Edition: versions 6.7.2 and below, and TIBCO FTL - Enterprise Edition: versions 6.7.2 and below.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43052" }, { "type": "WEB", "url": "https://www.tibco.com/services/support/advisories" }, { "type": "WEB", "url": "https://www.tibco.com/support/advisories/2022/01/tibco-security-advisory-january-11-2022-tibco-ftl-2021-43052" } ], "database_specific": { "cwe_ids": [ "CWE-798" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-01-11T19:15:00Z" } }