#VU63167 XML External Entity injection in TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server - CVE-2022-22774
Published: May 13, 2022
TIBCO Managed File Transfer Command Center
TIBCO Managed File Transfer Internet Server
TIBCO
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input in the DOM XML parser and SAX XML parser. A remote attacker can pass a specially crafted XML code and update, insert or delete access to data on the affected system and associated resources.