PT-2020-20644 · Tibco · Tibco Data Virtualization+1

Published

2020-08-18

·

Updated

2021-07-21

·

CVE-2020-9415

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TIBCO Data Virtualization versions 7.0.8 and below TIBCO Data Virtualization versions 8.0.0, 8.1.0, 8.1.1, and 8.2.0 TIBCO Data Virtualization for AWS Marketplace versions 8.2.0 and below
Description The issue allows a malicious authenticated user to download any arbitrary file from the affected system, provided the user has the necessary privileges to monitor the server. This requires the user to be authenticated and have operational capacity privileges.
Recommendations For TIBCO Data Virtualization versions 7.0.8 and below, update to a version above 7.0.8 to resolve the issue. For TIBCO Data Virtualization versions 8.0.0, 8.1.0, 8.1.1, and 8.2.0, update to a version above 8.2.0 to resolve the issue. For TIBCO Data Virtualization for AWS Marketplace versions 8.2.0 and below, update to a version above 8.2.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-9415

Affected Products

Tibco Data Virtualization
Tibco Data Virtualization For Aws Marketplace