SB2023120609 - Multiple vulnerabilities in Tyler Technologies Court Case Management Plus
Published: December 6, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Improper Authentication (CVE-ID: CVE-2023-6354)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within the Magistrate Court Case Management Plus. A remote attacker can manipulate the PDFViewer.aspx "filename" parameter and upload, delete and view arbitrary files.
2) Improper Authentication (CVE-ID: CVE-2023-6353)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within Civil and Criminal Electronic Filing. A remote attacker can manipulate the Upload.aspx "enky" parameter and upload, delete and view arbitrary files.
3) Files or Directories Accessible to External Parties (CVE-ID: CVE-2023-6375)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to files or directories accessible to external parties. A remote attacker can gain access to backups containing sensitive information such as database credentials.
4) Improper Authentication (CVE-ID: CVE-2023-6344)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within the Aquaforest TIFF Server feature. A remote attacker can use the tiffserver/te003.aspx or te004.aspx "ifolder" parameter and enumerate directories.
5) Improper Authentication (CVE-ID: CVE-2023-6343)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within the Aquaforest TIFF Server feature. A remote attacker can enumerate and access sensitive files using the tiffserver/tssp.aspx "FN" and "PN" parameters.
6) Improper Authentication (CVE-ID: CVE-2023-6342)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within the "pay for print" feature. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Remediation
Install update from vendor's website.
References
- https://www.tylertech.com/solutions/courts-public-safety/courts-justice
- https://github.com/qwell/disorder-in-the-court/blob/main/README-TylerTechnologies.md
- https://techcrunch.com/2023/11/30/us-court-records-systems-vulnerabilities-exposed-sealed-documents/
- https://www.cisa.gov/news-events/alerts/2023/11/30/multiple-vulnerabilities-affecting-web-based-court-case-and-document-management-systems
- https://www.aquaforest.com/blog/tiff-server-security-update
- https://www.aquaforest.com/blog/aquaforest-tiff-server-sunsetting