Tyler Technologies Court Case Management Plus use of Aquaforest TIFF Server te003.aspx and te004.aspx allows authentication bypass
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.9%
probabilidad de explotación
0.9%top 41% de las CVE
explotación observada
noninguna fuente lo reporta
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Tyler Technologies · Court Case Management PlusReferencias
https://github.com/qwell/disorder-in-the-court/blob/main/README-TylerTechnologies.mdhttps://techcrunch.com/2023/11/30/us-court-records-systems-vulnerabilities-exposed-sealed-documents/https://www.aquaforest.com/blog/aquaforest-tiff-server-sunsettinghttps://www.aquaforest.com/blog/tiff-server-security-updatehttps://www.cisa.gov/news-events/alerts/2023/11/30/multiple-vulnerabilities-affecting-web-based-court-case-and-document-management-systemshttps://www.tylertech.com/solutions/courts-public-safety/courts-justice