TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities
BID:49619
Info
TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 49619 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3423 CVE-2011-3424 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2011 12:00AM |
| Updated: | Sep 14 2011 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
TIBCO Slingshot 1.8 TIBCO Managed File Transfer Internet Server 7.1 TIBCO Managed File Transfer Command Center 7.1 |
| Not Vulnerable: | |
Discussion
TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities
TIBCO Managed File Transfer Products are prone to a cross-site scripting vulnerability and a session-fixation vulnerability.
Successfully exploiting these vulnerabilities will allow attackers to execute arbitrary script code in a user's browser in the context of the Web server process, access sensitive data, or hijack a user's session.
The following products are vulnerable:
TIBCO Managed File Transfer Internet Server 7.1.0 and earlier
TIBCO Managed File Transfer Command Center 7.1.0 and earlier
TIBCO Slingshot versions 1.8.0 and earlier
TIBCO Managed File Transfer Products are prone to a cross-site scripting vulnerability and a session-fixation vulnerability.
Successfully exploiting these vulnerabilities will allow attackers to execute arbitrary script code in a user's browser in the context of the Web server process, access sensitive data, or hijack a user's session.
The following products are vulnerable:
TIBCO Managed File Transfer Internet Server 7.1.0 and earlier
TIBCO Managed File Transfer Command Center 7.1.0 and earlier
TIBCO Slingshot versions 1.8.0 and earlier
Exploit / POC
TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit some of the issues, the attacker needs to entice a user to follow a malicious URI.
An attacker can use a browser to exploit these issues. To exploit some of the issues, the attacker needs to entice a user to follow a malicious URI.
Solution / Fix
TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TIBCO Managed File Transfer Products Session Fixation and Cross Site Scripting Vulnerabilities
References:
References:
- Managed File Transfer Solutions (TIBCO)
- TIBCO Homepage (TIBCO)
- General FAQ (TIBCO)
- TIBCO Managed File Transfer vulnerability (TIBCO)