Back to overview

CVE-2020-9412

CRITICAL
10.0
CVSS 3.1
Description
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, version 8.0.0.

Metadata

CVE ID
CVE-2020-9412
State
PUBLISHED
Assigner
tibco
Reserved
2020-02-26 00:00 UTC
Published
2020-06-09 17:00 UTC
Last updated
2024-09-17 00:35 UTC
Vendor / Product
TIBCO Software Inc. / TIBCO Managed File Transfer Platform Server for IBM i
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
TIBCO Software Inc. TIBCO Managed File Transfer Platform Server for IBM i — unspecified ≤ 7.1.0, 8.0.0
Weakness (CWE)
CWESourceDescription
— cna The impact of this vulnerability includes the possibility that an unauthenticated attacker could execute arbitrary commands on the system.
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview