TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.tibco.com/assets/blt423f06fbac6ee0c6/2015-003-advisory.txt | vendor advisory |
http://www.tibco.com/mk/advisory.jsp | vendor advisory |
http://www.securitytracker.com/id/1033678 | vdb entry |