TIBCO Managed File Transfer Platform Server Remote Code Execution Vulnerability
Published Mar 30, 2022
8.5
HIGHCVSS 3.1
EPSS 2.34%
Description
The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX and TIBCO Managed File Transfer Platform Server for z/Linux contain a difficult to exploit Remote Code Execution (RCE) vulnerability that allows a low privileged attacker with network access to execute arbitrary code on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX: versions 8.1.0 and below and TIBCO Managed File Transfer Platform Server for z/Linux: versions 8.1.0 and below.
Affected products
- Vendor TIBCO Software Inc. Product TIBCO Managed File Transfer Platform Server for UNIX Defaultunknown
Affected
- ≥ unspecified, ≤ 8.1.0
- Vendor TIBCO Software Inc. Product TIBCO Managed File Transfer Platform Server for z/Linux Defaultunknown
Affected
- ≥ unspecified, ≤ 8.1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| TIBCO Software Inc. | TIBCO Managed File Transfer Platform Server for UNIX | unknown | Affected
|
| TIBCO Software Inc. | TIBCO Managed File Transfer Platform Server for z/Linux | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
TIBCO has released updated versions of the affected components which address these issues.
TIBCO Managed File Transfer Platform Server for UNIX versions 8.1.0 and below update to version 8.1.1 or later TIBCO Managed File Transfer Platform Server for z/Linux versions 8.1.0 and below update to version 8.1.1 or later
No CWE recorded.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27915 Advisory
- https://www.tibco.com/services/support/advisories x_refsource_CONFIRMVendor Advisory
- https://www.tibco.com/support/advisories/2022/03/tibco-security-advisory-march-30-2022-tibco-managed-file-transfer-2022-22772 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27915 | Advisory | |
| https://www.tibco.com/services/support/advisories | x_refsource_CONFIRMVendor Advisory | |
| https://www.tibco.com/support/advisories/2022/03/tibco-security-advisory-march-30-2022-tibco-managed-file-transfer-2022-22772 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data