Security Advisory for TIBCO Managed File Transfer

Security Advisory for TIBCO Managed File Transfer

book

Article ID: KB0108127

calendar_today

Updated On:

Products Versions
TIBCO Managed File Transfer Internet Server -
TIBCO Slingshot -
TIBCO Vault -

Description

Description:
TIBCO Managed File Transfer vulnerabilities

Original release date: October 29, 2014
Last revised: October 29, 2014
Source: TIBCO Software Inc.

Systems Affected



  • TIBCO Managed File Transfer Internet Server 7.2.3 and earlier
  • TIBCO Managed File Transfer Command Center 7.2.3 and earlier
  • TIBCO Slingshot 1.9.2 and earlier
  • TIBCO Vault 1.1.0



The following components are affected:



  • TIBCO Managed File Transfer engine
  • TIBCO Slingshot server
  • TIBCO Vault server

Description


The TIBCO Managed File Transfer components listed above contain a critical vulnerability that may allow an agent to gain privileges and assume an identity.



TIBCO has released updated versions of the affected software products which address these issues. TIBCO strongly recommends sites running the affected components install the applicable update as described below.



Impact


The impact of this vulnerability is session integrity.



Solution


For each affected system, update to the corresponding software versions:



  • TIBCO Managed File Transfer Internet Server 7.2.4 or later
  • TIBCO Managed File Transfer Command Center 7.2.4 or later
  • TIBCO Slingshot 1.9.3 or later
  • TIBCO Vault 1.1.1 or later



References



http://www.tibco.com/mk/advisory.jsp
CVE: CVE-2014-7194

Environment

Product: TIBCO Managed File Transfer Internet Server Version: 7.2.3 and earlier OS: All Supported Operating Systems -------------------- Product: TIBCO Managed File Transfer Command Center Version: 7.2.3 and earlier OS: All Supported Operating Systems -------------------- Product: TIBCO Slingshot Version: 1.9.2 and earlier OS: All Supported Operating Systems -------------------- Product: TIBCO Vault Version: 1.1.0 OS: All Supported Operating Systems --------------------

Issue/Introduction

Security Advisory for TIBCO Managed File Transfer

Additional Information

CVE-2014-7194