PT-2023-32620 · Tyler Technologies · Court Case Management Plus
Jason Parker
·
Publicado
2023-11-30
·
Atualizado
2023-12-06
·
CVE-2023-6344
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Court Case Management Plus (affected versions not specified)
Tyler Technologies Court Case Management Plus (affected versions not specified)
Description
The issue concerns insufficient permission checks in public court record platforms from multiple vendors, allowing unauthorized public access to sealed, confidential, and unreleased information. A specific instance involves Tyler Technologies Court Case Management Plus, where a remote, unauthenticated attacker can enumerate directories using the
tiffserver/te003.aspx or te004.aspx API endpoints, specifically the ifolder parameter.Recommendations
For Court Case Management Plus, restrict access to the
tiffserver/te003.aspx and te004.aspx API endpoints to prevent directory enumeration.
For Tyler Technologies Court Case Management Plus, avoid using the ifolder parameter in the affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Court Case Management Plus