Improper Authentication in TIBCO Managed File Transfer Platform Server for IBM - CVE-2020-9411

 

Improper Authentication in TIBCO Managed File Transfer Platform Server for IBM - CVE-2020-9411

Published: June 10, 2020


Vulnerability identifier: #VU28937
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9411
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests in the "file transfer" component. A remote attacker can read and write any file on the file system accessible to the affected component.


Affected software

TIBCO Managed File Transfer Platform Server for IBM

How to mitigate CVE-2020-9411

Install updates from vendor's website.

TIBCO Managed File Transfer Platform Server for IBM - addressed in versions 7.1.1, 8.0.1

External References

Related Security Bulletins