First published: Tue Jun 09 2020(Updated: )
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected component. This vulnerability is exploitable when the configuration option 'Require Node Resp' is set to 'No'. In the event of a successful exploit, the attacker could theoretically read and write any file on the file system accessible to the affected component, thus fully affecting the confidentiality, integrity, and availability of the operating system hosting the deployment of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, version 8.0.0.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Managed File Transfer Platform Server | <=7.1.0 | |
TIBCO Managed File Transfer Platform Server | =8.0.0 | |
IBM i |
TIBCO has released updated versions of the affected components which address these issues. TIBCO Managed File Transfer Platform Server for IBM i versions 7.1.0 and below update to version 7.1.1 or higher TIBCO Managed File Transfer Platform Server for IBM i version 8.0.0 update to version 8.0.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-9411.
The severity of CVE-2020-9411 is critical.
The TIBCO Managed File Transfer Platform Server versions 7.1.0 and 8.0.0 are affected by CVE-2020-9411.
An attacker can exploit CVE-2020-9411 to perform unauthorized network file transfers to and from the file system accessible to the affected component.
No, IBM i systems are not vulnerable to CVE-2020-9411.
You can find more information about CVE-2020-9411 on the TIBCO website: [https://www.tibco.com/services/support/advisories](https://www.tibco.com/services/support/advisories) and [https://www.tibco.com/support/advisories/2020/06/tibco-security-advisory-june-9-2020-tibco-managed-file-transfer-2020-9411](https://www.tibco.com/support/advisories/2020/06/tibco-security-advisory-june-9-2020-tibco-managed-file-transfer-2020-9411)