Vulnerability Description
The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login URL for the affected system via a REST API. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: version 6.2.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tibco | Partnerexpress | 6.2.0 |
References
- http://www.tibco.com/services/support/advisoriesVendor Advisory
- https://www.tibco.com/support/advisories/2020/12/tibco-security-advisory-decembeVendor Advisory
- http://www.tibco.com/services/support/advisoriesVendor Advisory
- https://www.tibco.com/support/advisories/2020/12/tibco-security-advisory-decembeVendor Advisory
FAQ
What is CVE-2020-27147?
CVE-2020-27147 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login...
How severe is CVE-2020-27147?
CVE-2020-27147 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27147?
Check the references section above for vendor advisories and patch information. Affected products include: Tibco Partnerexpress.