CVE-2022-22774
Published on: Not Yet Published
Last Modified on: 05/19/2022 05:24:00 PM UTC
Certain versions of Managed File Transfer Command Center from Tibco contain the following vulnerability:
The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.0 and 8.4.1, TIBCO Managed File Transfer Internet Server: versions 8.3.1 and below, and TIBCO Managed File Transfer Internet Server: versions 8.4.0 and 8.4.1.
- CVE-2022-22774 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.1 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | HIGH |
CVSS2 Score: 6.4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
TIBCO Security Advisory: May 10, 2022 - TIBCO Managed File Transfer Command Center - CVE-2022-22774 | TIBCO Software | www.tibco.com text/html |
![]() |
Advisory | TIBCO Software | web.archive.org text/html Inactive LinkNot Archived |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tibco | Managed File Transfer Command Center | All | All | All | All |
Application | Tibco | Managed File Transfer Internet Server | All | All | All | All |
- cpe:2.3:a:tibco:managed_file_transfer_command_center:*:*:*:*:*:*:*:*:
- cpe:2.3:a:tibco:managed_file_transfer_internet_server:*:*:*:*:*:*:*:*:
Discovery Credit
TIBCO would like to extend its appreciation to Niv Levy for discovery of this vulnerability.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-22774 : The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Trans… twitter.com/i/web/status/1… | 2022-05-10 17:03:40 |
![]() |
CVE-2022-22774 | 2022-05-10 18:39:11 |