Products | Versions |
---|---|
TIBCO Managed File Transfer Platform Server for IBM i | 7.1.0 and below, 8.0.0 |
TIBCO Managed File Transfer Platform Server for IBM i Authentication Bypass
Original release date: June 9, 2020
Last revised: ---
Source: TIBCO Software Inc.
Description
The component listed above contains a vulnerability that theoretically allows
an attacker to perform unauthorized network file transfers to and from the
file system accessible to the affected component. This vulnerability is
exploitable when the configuration option 'Require Node Resp' is set to 'No'.
In the event of a successful exploit, the attacker could theoretically read
and write any file on the file system accessible to the affected component,
thus fully affecting the confidentiality, integrity, and availability of the
operating system hosting the deployment of the affected system.
Impact
The impact of this vulnerability includes the possibility that an attacker
could gain access to the contents of files they are otherwise not authorized
to see, and modify files they otherwise should not be able to change, and
affect the availability of the hosting system, by way of damaging critical
system files.
CVSS v3 Base Score: 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
References
http://www.tibco.com/services/support/advisories
CVE-2020-9411