PT-2010-5504 · Tibco · Tibco Activematrix Service Grid+4
Published
2010-12-17
·
Updated
2010-12-20
·
CVE-2010-4495
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIBCO ActiveMatrix Service Grid versions 3.0.0 through 3.1.0
TIBCO ActiveMatrix Service Bus versions 3.0.0 through 3.0.1
TIBCO ActiveMatrix BusinessWorks Service Engine version 5.9.0
TIBCO ActiveMatrix BPM versions 1.0.1 through 1.0.2
TIBCO Silver BPM Service version 1.0.1
TIBCO Silver CAP Service version 1.0.0
Description
The issue allows remote authenticated users to execute arbitrary code via vectors related to JMX connections.
Recommendations
For TIBCO ActiveMatrix Service Grid versions 3.0.0 through 3.1.0, update to a version that addresses the issue.
For TIBCO ActiveMatrix Service Bus versions 3.0.0 through 3.0.1, update to a version that addresses the issue.
For TIBCO ActiveMatrix BusinessWorks Service Engine version 5.9.0, update to a version that addresses the issue.
For TIBCO ActiveMatrix BPM versions 1.0.1 through 1.0.2, update to a version that addresses the issue.
For TIBCO Silver BPM Service version 1.0.1, update to a version that addresses the issue.
For TIBCO Silver CAP Service version 1.0.0, update to a version that addresses the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tibco Activematrix Bpm
Tibco Activematrix Businessworks Service Engine
Tibco Activematrix Service Bus
Tibco Activematrix Service Grid
Tibco Silver Bpm Service