TIBCO takes its security responsibilities very seriously. This page provides information about TIBCO security and how customers or security researchers can contact TIBCO to report or ask about a security issue.
TIBCO Security Advisory: June 30, 2020 - TIBCO Managed File Transfer - 2020-9413
TIBCO Managed File Transfer reflected XSS vulerability
Original release date: June 30, 2020
Source: TIBCO Software Inc.
- TIBCO Managed File Transfer Command Center versions 8.2.1 and below
- TIBCO Managed File Transfer Internet Server versions 8.2.1 and below
The following components are affected:
- MFT Browser file transfer client
- MFT Browser admin client
The components listed above contain a vulnerability that theoretically allows an attacker to craft an URL that will execute arbitrary commands on the affected system. If the attacker convinces an authenticated user with a currently active session to enter or click on the URL the commands will be executed on the affected system.
The impact of this vulnerability includes the possibility that an attacker can gain access to the session ID of the affected user's session and take any action the affected user has privilege to perform.
CVSS v3 Base Score: 6.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
TIBCO has released updated versions of the affected systems which address this issue:
- TIBCO Managed File Transfer Command Center versions 8.2.1 and below update to version 8.3.0 or higher
- TIBCO Managed File Transfer Internet Server versions 8.2.1 and below update to version 8.3.0 or higher