PT-2025-3775 · Tata Consultancy Services · Tcs Bancs

Zaid Shaikh

·

Published

2025-01-04

·

Updated

2025-01-22

·

CVE-2025-0202

CVSS v2.0

5.2

Medium

VectorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TCS BaNCS version 10
Description A vulnerability was found in TCS BaNCS, affecting an unknown part of the file /REPORTS/REPORTS SHOW FILE.jsp. The manipulation of the FilePath argument leads to file inclusion. The real existence of this vulnerability is still doubted at the moment.
Recommendations For TCS BaNCS version 10, as a temporary workaround, consider restricting access to the /REPORTS/REPORTS SHOW FILE.jsp file until the issue is resolved. Avoid manipulating the FilePath argument in the affected file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-0202

Affected Products

Tcs Bancs