Unauthenticated Access to Authenticated Login URL in TIBCO PartnerExpress REST API

Unauthenticated Access to Authenticated Login URL in TIBCO PartnerExpress REST API

CVE-2020-27147 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login URL for the affected system via a REST API. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: version 6.2.0.

Learn more about our Api Penetration Testing.