First published: Wed Apr 30 2014(Updated: )
TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Slingshot | <=1.9.0 | |
TIBCO Slingshot | =1.7.0 | |
TIBCO Slingshot | =1.8.0 | |
TIBCO Slingshot | =1.8.1 | |
TIBCO Vault | <=1.0.0 | |
TIBCO Managed File Transfer Command Center | <=7.2.1 | |
TIBCO Managed File Transfer Command Center | =6.7 | |
TIBCO Managed File Transfer Command Center | =7.0 | |
TIBCO Managed File Transfer Command Center | =7.0.1 | |
TIBCO Managed File Transfer Command Center | =7.1.0 | |
TIBCO Managed File Transfer Command Center | =7.2.0 | |
TIBCO Managed File Transfer Internet Server | <=7.2.1 | |
TIBCO Managed File Transfer Internet Server | =6.7 | |
TIBCO Managed File Transfer Internet Server | =7.0 | |
TIBCO Managed File Transfer Internet Server | =7.0.1 | |
TIBCO Managed File Transfer Internet Server | =7.1.0 | |
TIBCO Managed File Transfer Internet Server | =7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2545 has a medium severity rating, indicating potential for sensitive information disclosure.
To fix CVE-2014-2545, update TIBCO Managed File Transfer Internet Server, Managed File Transfer Command Center, Slingshot, and Vault to versions 7.2.2 or higher.
CVE-2014-2545 affects TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1.
Yes, CVE-2014-2545 can be exploited remotely by attackers through crafted HTTP requests.
CVE-2014-2545 can potentially expose sensitive application data and configuration details.