XML External Entity injection in TIBCO Managed File Transfer Internet Server and TIBCO Managed File Transfer Command Center - CVE-2022-22774
Published: May 13, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input in the DOM XML parser and SAX XML parser. A remote attacker can pass a specially crafted XML code and update, insert or delete access to data on the affected system and associated resources.
Affected software
TIBCO Managed File Transfer Command Center
How to mitigate CVE-2022-22774
TIBCO Managed File Transfer Command Center - addressed in versions 8.3.2, 8.4.2