Authentication Bypass Vulnerability in TIBCO Managed File Transfer Products
CVE-2017-5531
8HIGH
Key Information:
- Vendor
- Tibco
- Vendor
- CVE Published:
- 17 October 2017
Summary
A vulnerability exists in TIBCO Managed File Transfer products, where enabled Administrator Services allow any authenticated user to escalate their privileges, potentially leading to unauthorized administrative control over the Managed File Transfer web applications. This exposes critical functionality and sensitive data to unauthorized access, demanding immediate attention and remediation.
Affected Version(s)
TIBCO Managed File Transfer Command Center 8.0.0
TIBCO Managed File Transfer Command Center 8.0.1
TIBCO Managed File Transfer Internet Server 8.0.0
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved