Advisory Published
Updated

CVE-2020-9415: TIBCO Data Virtualization

First published: Tue Aug 18 2020(Updated: )

The TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains a vulnerability that theoretically allows a malicious authenticated user to download any arbitrary file from the affected system. The user must be authenticated and have privileges required to monitor the server in an operational capacity. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 7.0.8 and below, versions 8.0.0, 8.1.0, 8.1.1, and 8.2.0 and TIBCO Data Virtualization for AWS Marketplace: versions 8.2.0 and below.

Credit: security@tibco.com

Affected SoftwareAffected VersionHow to fix
TIBCO Data Virtualization<=7.0.8
TIBCO Data Virtualization=8.0.0
TIBCO Data Virtualization=8.1.0
TIBCO Data Virtualization=8.1.1
TIBCO Data Virtualization=8.2.0
TIBCO Data Virtualization for AWS Marketplace<=8.2.0

Remedy

TIBCO has released updated versions of the affected components which address these issues. TIBCO Data Virtualization versions 7.0.8 and below update to version 7.0.9 or higher TIBCO Data Virtualization versions 8.0.0, 8.1.0, 8.1.1, and 8.2.0 update to version 8.3.0 or higher TIBCO Data Virtualization for AWS Marketplace versions 8.2.0 and below update to version 8.3.0 or higher

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-9415?

    CVE-2020-9415 is a vulnerability in the TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace.

  • How does CVE-2020-9415 affect TIBCO Data Virtualization?

    CVE-2020-9415 allows a malicious authenticated user to download any arbitrary file from the affected system in TIBCO Data Virtualization.

  • Is TIBCO Data Virtualization version 7.0.8 affected by CVE-2020-9415?

    Yes, TIBCO Data Virtualization version 7.0.8 is affected by CVE-2020-9415.

  • How severe is CVE-2020-9415?

    CVE-2020-9415 has a severity rating of medium (6.5).

  • How can I fix the vulnerability CVE-2020-9415?

    To fix the vulnerability CVE-2020-9415, users should apply the necessary patches or updates provided by TIBCO Software Inc.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203