CVE-2017-5531

HIGHCVSS 8/10EPSS 1.28%

Last modified

CVE-2017-5531 is a high-severity vulnerability rated 8/10 on the CVSS scale. Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Internet Server versions 8.0.0 and 8.0.1 that enable the Administrator Service may be affected by a vulnerability which may allow any authenticated user to gain administrative control of Managed File Transfer web applications.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.

Description

Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Internet Server versions 8.0.0 and 8.0.1 that enable the Administrator Service may be affected by a vulnerability which may allow any authenticated user to gain administrative control of Managed File Transfer web applications.

Metrics

CVSS 3.0
8/10

CVSS:3.0/A:H/AC:L/AV:N/C:H/I:H/PR:L/S:U/UI:R

EPSS Probability
1.28%

66.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
TibcoManaged File Transfer Command Center8.0.0
TibcoManaged File Transfer Command Center8.0.1
TibcoManaged File Transfer Internet Server8.0.0
TibcoManaged File Transfer Internet Server8.0.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-5531?
Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Internet Server versions 8.0.0 and 8.0.1 that enable the Administrator Service may be affected by a vulnerability which may allow any authenticated user to gain administrative control of Managed File Transfer web applications.
How severe is CVE-2017-5531?
CVE-2017-5531 has a CVSS score of 8/10 (HIGH severity). The EPSS model estimates a 1.28% probability of exploitation in the next 30 days.
How do I fix CVE-2017-5531?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2017

Are you affected by CVE-2017-5531?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST