PT-2010-5504 · Tibco · Tibco Activematrix Service Grid+4

Published

2010-12-17

·

Updated

2010-12-20

·

CVE-2010-4495

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TIBCO ActiveMatrix Service Grid versions 3.0.0 through 3.1.0 TIBCO ActiveMatrix Service Bus versions 3.0.0 through 3.0.1 TIBCO ActiveMatrix BusinessWorks Service Engine version 5.9.0 TIBCO ActiveMatrix BPM versions 1.0.1 through 1.0.2 TIBCO Silver BPM Service version 1.0.1 TIBCO Silver CAP Service version 1.0.0
Description The issue allows remote authenticated users to execute arbitrary code via vectors related to JMX connections.
Recommendations For TIBCO ActiveMatrix Service Grid versions 3.0.0 through 3.1.0, update to a version that addresses the issue. For TIBCO ActiveMatrix Service Bus versions 3.0.0 through 3.0.1, update to a version that addresses the issue. For TIBCO ActiveMatrix BusinessWorks Service Engine version 5.9.0, update to a version that addresses the issue. For TIBCO ActiveMatrix BPM versions 1.0.1 through 1.0.2, update to a version that addresses the issue. For TIBCO Silver BPM Service version 1.0.1, update to a version that addresses the issue. For TIBCO Silver CAP Service version 1.0.0, update to a version that addresses the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-4495

Affected Products

Tibco Activematrix Bpm
Tibco Activematrix Businessworks Service Engine
Tibco Activematrix Service Bus
Tibco Activematrix Service Grid
Tibco Silver Bpm Service