Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-28827 Details

Description

The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition for z/Linux, TIBCO Administrator - Enterprise Edition for z/Linux, TIBCO Runtime Agent, TIBCO Runtime Agent, TIBCO Runtime Agent for z/Linux, and TIBCO Runtime Agent for z/Linux contains an easily exploitable vulnerability that allows an unauthenticated attacker to social engineer a legitimate user with network access to execute a Stored XSS attack targeting the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition: versions 5.10.2 and below, TIBCO Administrator - Enterprise Edition: versions 5.11.0 and 5.11.1, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric: versions 5.10.2 and below, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric: versions 5.11.0 and 5.11.1, TIBCO Administrator - Enterprise Edition for z/Linux: versions 5.10.2 and below, TIBCO Administrator - Enterprise Edition for z/Linux: versions 5.11.0 and 5.11.1, TIBCO Runtime Agent: versions 5.10.2 and below, TIBCO Runtime Agent: versions 5.11.0 and 5.11.1, TIBCO Runtime Agent for z/Linux: versions 5.10.2 and below, and TIBCO Runtime Agent for z/Linux: versions 5.11.0 and 5.11.1.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')[email protected]

Affected Products

ProductVersions
tibco administrator
<= 5.10.2
5.11.0
5.11.1

CPE

  • cpe:2.3:a:tibco:administrator:*:*:*:*:enterprise:*:*:*
  • cpe:2.3:a:tibco:administrator:*:*:*:*:enterprise:silver_fabric:*:*
  • cpe:2.3:a:tibco:administrator:*:*:*:*:enterprise:z/linux:*:*
  • cpe:2.3:a:tibco:administrator:5.11.0:*:*:*:enterprise:*:*:*
  • cpe:2.3:a:tibco:administrator:5.11.0:*:*:*:enterprise:silver_fabric:*:*
  • cpe:2.3:a:tibco:administrator:5.11.0:*:*:*:enterprise:z/linux:*:*
  • cpe:2.3:a:tibco:administrator:5.11.1:*:*:*:enterprise:*:*:*
  • cpe:2.3:a:tibco:administrator:5.11.1:*:*:*:enterprise:silver_fabric:*:*
  • cpe:2.3:a:tibco:administrator:5.11.1:*:*:*:enterprise:z/linux:*:*

Remediation

  • No remediation found in references.
tibco runtime agent
<= 5.10.2
5.11.0
5.11.1

CPE

  • cpe:2.3:a:tibco:runtime_agent:*:*:*:*:*:*:*:*
  • cpe:2.3:a:tibco:runtime_agent:*:*:*:*:*:z/linux:*:*
  • cpe:2.3:a:tibco:runtime_agent:5.11.0:*:*:*:*:*:*:*
  • cpe:2.3:a:tibco:runtime_agent:5.11.0:*:*:*:*:z/linux:*:*
  • cpe:2.3:a:tibco:runtime_agent:5.11.1:*:*:*:*:*:*:*
  • cpe:2.3:a:tibco:runtime_agent:5.11.1:*:*:*:*:z/linux:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-28827
NVD Published Date:
Apr 20, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]