First published: Tue Dec 11 2018(Updated: )
The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Managed File Transfer Internet Server contains vulnerabilities where an authenticated user with specific privileges can gain access to credentials to other systems. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions up to and including 7.3.2; 8.0.0; 8.0.1; 8.0.2; 8.1.0, and TIBCO Managed File Transfer Internet Server: versions up to and including 7.3.2; 8.0.0; 8.0.1; 8.0.2; 8.1.0.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Managed File Transfer Command Center | <=7.3.2 | |
TIBCO Managed File Transfer Command Center | >=8.0.0<=8.0.2 | |
TIBCO Managed File Transfer Command Center | =8.1.0 | |
TIBCO Managed File Transfer Internet Server | <=7.3.2 | |
TIBCO Managed File Transfer Internet Server | >=8.0.0<=8.0.2 | |
TIBCO Managed File Transfer Internet Server | =8.1.0 |
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Managed File Transfer Command Center versions 7.3.2 and below update to version 7.3.3 or higher TIBCO Managed File Transfer Command Center versions 8.0.0, 8.0.1 and 8.0.2 update to version 8.0.3 or higher TIBCO Managed File Transfer Command Center version 8.1.0 update to version 8.1.1 or higher TIBCO Managed File Transfer Internet Server versions 7.3.2 and below update to version 7.3.3 or higher TIBCO Managed File Transfer Internet Server versions 8.0.0, 8.0.1 and 8.0.2 update to version 8.0.3 or higher TIBCO Managed File Transfer Internet Server version 8.1.0 update to version 8.1.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18810 is a vulnerability in the Administrator Service component of TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server.
CVE-2018-18810 has a severity rating of 9.9 (critical).
CVE-2018-18810 affects TIBCO Managed File Transfer Command Center versions up to and including 7.3.2, 8.0.0 to 8.0.2, and 8.1.0. It also affects TIBCO Managed File Transfer Internet Server versions up to and including 7.3.2, 8.0.0 to 8.0.2, and 8.1.0.
An authenticated user with specific privileges can exploit CVE-2018-18810 to gain access to credentials of other systems.
You can find more information about CVE-2018-18810 in the TIBCO Security Advisories page (http://www.tibco.com/services/support/advisories) and the TIBCO Managed File Transfer advisory for December 11, 2018 (https://www.tibco.com/support/advisories/2018/12/tibco-security-advisory-december-11-2018-tibco-managed-file-transfer).