PT-2008-1506 · Tibco · Tibco Enterprise Message Service+2
Publicado
2008-01-16
·
Atualizado
2017-07-29
·
CVE-2007-5657
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIBCO SmartSockets RTserver versions 6.8.0 and earlier
TIBCO RTworks versions prior to 4.0.4
TIBCO Enterprise Message Service (EMS) versions 4.0.0 through 4.4.1
Description
The issue allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.
Recommendations
For TIBCO SmartSockets RTserver versions 6.8.0 and earlier, update to a version later than 6.8.0.
For TIBCO RTworks versions prior to 4.0.4, update to version 4.0.4 or later.
For TIBCO Enterprise Message Service (EMS) versions 4.0.0 through 4.4.1, update to a version later than 4.4.1.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tibco Enterprise Message Service
Tibco Rtworks
Tibco Smartsockets Rtserver