TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request.
| Software | From | Fixed in |
|---|---|---|
| tibco / slingshot | 1.8.0 | 1.8.0.x |
| tibco / slingshot | 1.8.1 | 1.8.1.x |
| tibco / slingshot | - | 1.9.0.x |
| tibco / slingshot | 1.7.0 | 1.7.0.x |
| tibco / vault | - | 1.0.0.x |
| tibco / managed_file_transfer_command_center | 7.1.0 | 7.1.0.x |
| tibco / managed_file_transfer_command_center | 6.7 | 6.7.x |
| tibco / managed_file_transfer_command_center | 7.2.0 | 7.2.0.x |
| tibco / managed_file_transfer_command_center | 7.0.1 | 7.0.1.x |
| tibco / managed_file_transfer_command_center | - | 7.2.1.x |
| tibco / managed_file_transfer_command_center | 7.0 | 7.0.x |
| tibco / managed_file_transfer_internet_server | 7.0.1 | 7.0.1.x |
| tibco / managed_file_transfer_internet_server | 6.7 | 6.7.x |
| tibco / managed_file_transfer_internet_server | 7.1.0 | 7.1.0.x |
| tibco / managed_file_transfer_internet_server | - | 7.2.1.x |
| tibco / managed_file_transfer_internet_server | 7.2.0 | 7.2.0.x |
| tibco / managed_file_transfer_internet_server | 7.0 | 7.0.x |