PT-2023-32620 · Tyler Technologies · Court Case Management Plus
Jason Parker
·
Published
2023-11-30
·
Updated
2023-12-06
·
CVE-2023-6344
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Court Case Management Plus (affected versions not specified)
Tyler Technologies Court Case Management Plus (affected versions not specified)
Description
The issue concerns insufficient permission checks in public court record platforms from multiple vendors, allowing unauthorized public access to sealed, confidential, and unreleased information. A specific instance involves Tyler Technologies Court Case Management Plus, where a remote, unauthenticated attacker can enumerate directories using the
tiffserver/te003.aspx or te004.aspx API endpoints, specifically the ifolder parameter.Recommendations
For Court Case Management Plus, restrict access to the
tiffserver/te003.aspx and te004.aspx API endpoints to prevent directory enumeration.
For Tyler Technologies Court Case Management Plus, avoid using the ifolder parameter in the affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Court Case Management Plus