CVE-2020-9412: TIBCO Managed File Transfer Platform Server for IBM i Arbitrary Command Execution
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, version 8.0.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-9412?
CVE-2020-9412 is a vulnerability in TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server that allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer.
What is the severity of CVE-2020-9412?
CVE-2020-9412 has a severity rating of critical, with a severity value of 9.8.
Which versions of TIBCO Managed File Transfer Platform Server are affected by CVE-2020-9412?
The affected versions of TIBCO Managed File Transfer Platform Server are 7.1.0 and 8.0.0.
How can the vulnerability be exploited?
The vulnerability in TIBCO Managed File Transfer Platform Server can be exploited by executing arbitrary commands after a failed file transfer.
Are IBM i systems affected by CVE-2020-9412?
No, IBM i systems are not vulnerable to CVE-2020-9412.