CVE-2020-9415: TIBCO Data Virtualization
The TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains a vulnerability that theoretically allows a malicious authenticated user to download any arbitrary file from the affected system. The user must be authenticated and have privileges required to monitor the server in an operational capacity. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 7.0.8 and below, versions 8.0.0, 8.1.0, 8.1.1, and 8.2.0 and TIBCO Data Virtualization for AWS Marketplace: versions 8.2.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-9415?
CVE-2020-9415 is a vulnerability in the TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace.
How does CVE-2020-9415 affect TIBCO Data Virtualization?
CVE-2020-9415 allows a malicious authenticated user to download any arbitrary file from the affected system in TIBCO Data Virtualization.
Is TIBCO Data Virtualization version 7.0.8 affected by CVE-2020-9415?
Yes, TIBCO Data Virtualization version 7.0.8 is affected by CVE-2020-9415.
How severe is CVE-2020-9415?
CVE-2020-9415 has a severity rating of medium (6.5).
How can I fix the vulnerability CVE-2020-9415?
To fix the vulnerability CVE-2020-9415, users should apply the necessary patches or updates provided by TIBCO Software Inc.