XML External Entity injection in TIBCO Managed File Transfer Internet Server and TIBCO Managed File Transfer Command Center - CVE-2022-22774

 

XML External Entity injection in TIBCO Managed File Transfer Internet Server and TIBCO Managed File Transfer Command Center - CVE-2022-22774

Published: May 13, 2022


Vulnerability identifier: #VU63167
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2022-22774
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied XML input in the DOM XML parser and SAX XML parser. A remote attacker can pass a specially crafted XML code and update, insert or delete access to data on the affected system and associated resources.


Affected software

TIBCO Managed File Transfer Internet Server
TIBCO Managed File Transfer Command Center

How to mitigate CVE-2022-22774

Install updates from vendor's website.

TIBCO Managed File Transfer Internet Server - addressed in versions 8.3.2, 8.4.2
TIBCO Managed File Transfer Command Center - addressed in versions 8.3.2, 8.4.2

External References

Related Security Bulletins