CVE-2018-18810: TIBCO Managed File Transfer Credentials Disclosure
The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Managed File Transfer Internet Server contains vulnerabilities where an authenticated user with specific privileges can gain access to credentials to other systems. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions up to and including 7.3.2; 8.0.0; 8.0.1; 8.0.2; 8.1.0, and TIBCO Managed File Transfer Internet Server: versions up to and including 7.3.2; 8.0.0; 8.0.1; 8.0.2; 8.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2018-18810?
CVE-2018-18810 is a vulnerability in the Administrator Service component of TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server.
How severe is CVE-2018-18810?
CVE-2018-18810 has a severity rating of 9.9 (critical).
Which TIBCO software versions are affected by CVE-2018-18810?
CVE-2018-18810 affects TIBCO Managed File Transfer Command Center versions up to and including 7.3.2, 8.0.0 to 8.0.2, and 8.1.0. It also affects TIBCO Managed File Transfer Internet Server versions up to and including 7.3.2, 8.0.0 to 8.0.2, and 8.1.0.
How can an authenticated user exploit CVE-2018-18810?
An authenticated user with specific privileges can exploit CVE-2018-18810 to gain access to credentials of other systems.
Where can I find more information about CVE-2018-18810?
You can find more information about CVE-2018-18810 in the TIBCO Security Advisories page (http://www.tibco.com/services/support/advisories) and the TIBCO Managed File Transfer advisory for December 11, 2018 (https://www.tibco.com/support/advisories/2018/12/tibco-security-advisory-december-11-2018-tibco-managed-file-transfer).