CVE-2023-6343
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is similar to CVE-2020-9323. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.
Affected (1)
Products: Tylertech: Court Case Management Plus
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (12)
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory
https://techcrunch.com/2023/11/30/us-court-records-systems-vulnerabilities-exposed-sealed-documents/
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Press/Media CoverageThird Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party AdvisoryUS Government Resource
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://techcrunch.com/2023/11/30/us-court-records-systems-vulnerabilities-exposed-sealed-documents/
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Timeline
No history available yet.