PT-2011-2527 · Tibco · Tibco Rendezvous+4

Published

2011-02-04

·

Updated

2017-08-17

·

CVE-2011-0649

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TIBCO Rendezvous versions 8.2.1 through 8.3.0 TIBCO Enterprise Message Service (EMS) versions 5.1.0 through 6.0.0 TIBCO Runtime Agent (TRA) versions 5.6.2 through 5.7.0 TIBCO Silver BPM Service version prior to 1.0.4 TIBCO Silver CAP Service version prior to 1.0.2 TIBCO Silver BusinessWorks Service version 1.0.0
Description The issue allows local users to gain root privileges via unknown vectors related to SUID and certain daemons, including (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd), when running on Unix systems.
Recommendations For TIBCO Rendezvous versions 8.2.1 through 8.3.0, consider disabling the rvrd, rvsd, and rvsrd daemons until a patch is available. For TIBCO Enterprise Message Service (EMS) versions 5.1.0 through 6.0.0, restrict access to the tibemsd daemon to minimize the risk of exploitation. For TIBCO Runtime Agent (TRA) versions 5.6.2 through 5.7.0, avoid using SUID-related functionality until the issue is resolved. For TIBCO Silver BPM Service version prior to 1.0.4, update to version 1.0.4 or later. For TIBCO Silver CAP Service version prior to 1.0.2, update to version 1.0.2 or later. For TIBCO Silver BusinessWorks Service version 1.0.0, consider applying configuration changes to restrict SUID-related access until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-0649

Affected Products

Tibco Enterprise Message Service
Tibco Rendezvous
Tibco Runtime Agent
Tibco Silver Bpm Service
Tibco Silver Businessworks Service