Back to overview

CVE-2020-9411

CRITICAL
10.0
CVSS 3.1
Description
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected component. This vulnerability is exploitable when the configuration option 'Require Node Resp' is set to 'No'. In the event of a successful exploit, the attacker could theoretically read and write any file on the file system accessible to the affected component, thus fully affecting the confidentiality, integrity, and availability of the operating system hosting the deployment of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, version 8.0.0.

Metadata

CVE ID
CVE-2020-9411
State
PUBLISHED
Assigner
tibco
Reserved
2020-02-26 00:00 UTC
Published
2020-06-09 17:00 UTC
Last updated
2024-09-16 23:36 UTC
Vendor / Product
TIBCO Software Inc. / TIBCO Managed File Transfer Platform Server for IBM i
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
TIBCO Software Inc. TIBCO Managed File Transfer Platform Server for IBM i unspecified ≤ 7.1.0, 8.0.0
Weakness (CWE)
CWESourceDescription
cna The impact of this vulnerability includes the possibility that an attacker could gain access to the contents of files they are otherwise not authorized to see, and modify files they otherwise should not be able to change, and affect the availability of the hosting system, by way of damaging critical system files.
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview