Six critical remote vulnerabilities in TIBCO SmartPGM FX

Credit: Andy Davis
Risk: High
Local: No
Remote: Yes

IRM have discovered six critical remote vulnerabilities in TIBCO SmartPGM FX. Five of these vulnerabilities could potentially result in an attacker gaining remote administrative control of the server on which SmartPGM FX is running and therefore, also allow access to any data stored on or being communicated by the server. The final vulnerability, a Denial of Service attack, would stop the SmartPGM FX service so that file transfers could not be performed. More information can be found at the following location: Once TIBCO has produced either workarounds or patches to mitigate these vulnerabilities, IRM will release advisories which will include full technical details.

