Authentication Bypass Vulnerability in TIBCO Managed File Transfer Products
CVE-2017-5531

8HIGH

Key Information:

Summary

A vulnerability exists in TIBCO Managed File Transfer products, where enabled Administrator Services allow any authenticated user to escalate their privileges, potentially leading to unauthorized administrative control over the Managed File Transfer web applications. This exposes critical functionality and sensitive data to unauthorized access, demanding immediate attention and remediation.

Affected Version(s)

TIBCO Managed File Transfer Command Center 8.0.0

TIBCO Managed File Transfer Command Center 8.0.1

TIBCO Managed File Transfer Internet Server 8.0.0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.