First published: Tue Jun 09 2020(Updated: )
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, version 8.0.0.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Managed File Transfer Platform Server | <=7.1.0 | |
TIBCO Managed File Transfer Platform Server | =8.0.0 | |
IBM i |
TIBCO has released updated versions of the affected components which address these issues. TIBCO Managed File Transfer Platform Server for IBM i versions 7.1.0 and below update to version 7.1.1 or higher TIBCO Managed File Transfer Platform Server for IBM i version 8.0.0 update to version 8.0.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9412 is a vulnerability in TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server that allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer.
CVE-2020-9412 has a severity rating of critical, with a severity value of 9.8.
The affected versions of TIBCO Managed File Transfer Platform Server are 7.1.0 and 8.0.0.
The vulnerability in TIBCO Managed File Transfer Platform Server can be exploited by executing arbitrary commands after a failed file transfer.
No, IBM i systems are not vulnerable to CVE-2020-9412.