PT-2020-20642 · Tibco · Tibco Managed File Transfer Internet Server+1
Published
2020-06-30
·
Updated
2020-07-10
·
CVE-2020-9413
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIBCO Managed File Transfer Command Center versions 8.2.1 and below
TIBCO Managed File Transfer Internet Server versions 8.2.1 and below
Description
The issue allows an attacker to craft a URL that can execute arbitrary commands on the affected system. This can happen if an authenticated user with an active session is convinced to enter or click on the malicious URL.
Recommendations
For TIBCO Managed File Transfer Command Center versions 8.2.1 and below, update to a version above 8.2.1 to resolve the issue.
For TIBCO Managed File Transfer Internet Server versions 8.2.1 and below, update to a version above 8.2.1 to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tibco Managed File Transfer Command Center
Tibco Managed File Transfer Internet Server