Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22774

Опубликовано: 10 мая 2022
Источник: nvd
CVSS3: 8.6
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.0 and 8.4.1, TIBCO Managed File Transfer Internet Server: versions 8.3.1 and below, and TIBCO Managed File Transfer Internet Server: versions 8.4.0 and 8.4.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tibco:managed_file_transfer_command_center:*:*:*:*:*:*:*:*
Версия до 8.3.2 (исключая)
cpe:2.3:a:tibco:managed_file_transfer_command_center:*:*:*:*:*:*:*:*
Версия от 8.4.0 (включая) до 8.4.2 (исключая)
cpe:2.3:a:tibco:managed_file_transfer_internet_server:*:*:*:*:*:*:*:*
Версия до 8.3.2 (исключая)
cpe:2.3:a:tibco:managed_file_transfer_internet_server:*:*:*:*:*:*:*:*
Версия от 8.4.0 (включая) до 8.4.2 (исключая)

EPSS

Процентиль: 71%
0.00661
Низкий

8.6 High

CVSS3

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.0 and 8.4.1, TIBCO Managed File Transfer Internet Server: versions 8.3.1 and below, and TIBCO Managed File Transfer Internet Server: versions 8.4.0 and 8.4.1.

EPSS

Процентиль: 71%
0.00661
Низкий

8.6 High

CVSS3

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611