Security Advisory regarding TIBCO Managed File Transfer Platform Server for IBM i - CVE-2020-1941

Security Advisory regarding TIBCO Managed File Transfer Platform Server for IBM i - CVE-2020-1941

book

Article ID: KB0108042

calendar_today

Updated On:

Products Versions
TIBCO Managed File Transfer Platform Server for IBM i 7.1.0 and below, 8.0.0

Description

TIBCO Managed File Transfer Platform Server for IBM i Authentication Bypass

  Original release date: June 9, 2020
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The component listed above contains a vulnerability that theoretically allows
  an attacker to perform unauthorized network file transfers to and from the
  file system accessible to the affected component. This vulnerability is
  exploitable when the configuration option 'Require Node Resp' is set to 'No'.
  In the event of a successful exploit, the attacker could theoretically read
  and write any file on the file system accessible to the affected component,
  thus fully affecting the confidentiality, integrity, and availability of the
  operating system hosting the deployment of the affected system.

Impact

  The impact of this vulnerability includes the possibility that an attacker
  could gain access to the contents of files they are otherwise not authorized
  to see, and modify files they otherwise should not be able to change, and
  affect the availability of the hosting system, by way of damaging critical
  system files.

  CVSS v3 Base Score: 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)


References

  http://www.tibco.com/services/support/advisories
  CVE-2020-9411

Environment

Systems Affected   TIBCO Managed File Transfer Platform Server for IBM i versions 7.1.0 and     below   TIBCO Managed File Transfer Platform Server for IBM i version 8.0.0   The following component is affected:     * file transfer

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO Managed File Transfer Platform Server for IBM i versions 7.1.0 and
    below update to version 7.1.1 or higher
  TIBCO Managed File Transfer Platform Server for IBM i version 8.0.0 update
    to version 8.0.1 or higher

  For an alternate remediation, change the configuration option 'Require Node
  Resp' to 'Yes', and also explicitly add all of the nodes accessing the
  affected system that have not yet been added to the configuration.
 

Issue/Introduction

Security Advisory regarding TIBCO Managed File Transfer Platform Server for IBM i Authentication Bypass

Additional Information

  http://www.tibco.com/services/support/advisories
  CVE-2020-9411