PT-2020-20643 · Tibco · Tibco Managed File Transfer Internet Server+1
Published
2020-06-30
·
Updated
2020-07-10
·
CVE-2020-9414
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIBCO Managed File Transfer Command Center versions 8.2.1 and below
TIBCO Managed File Transfer Internet Server versions 8.2.1 and below
Description
The issue allows an authenticated user with specific permissions to obtain the session identifier of another user, which could provide administrative rights or file transfer permissions when replayed.
Recommendations
For TIBCO Managed File Transfer Command Center versions 8.2.1 and below, update to a version above 8.2.1 to resolve the issue.
For TIBCO Managed File Transfer Internet Server versions 8.2.1 and below, update to a version above 8.2.1 to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tibco Managed File Transfer Command Center
Tibco Managed File Transfer Internet Server