Vulnerability CVE-2007-5657


Published: 2008-01-15   Modified: 2012-02-12

Description:
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Tibco -> Enterprise message service 
Tibco -> Rtworks 
Tibco -> Smartsockets rtserver 

 References:
http://www.vupen.com/english/advisories/2008/0173
http://www.tibco.com/resources/mk/sspfm_security_advisory_20080115.txt
http://www.tibco.com/resources/mk/smartsockets_security_advisory_20080115.txt
http://www.tibco.com/resources/mk/ems_security_advisory_20080115.txt
http://www.tibco.com/mk/advisory.jsp
http://www.securityfocus.com/bid/27295
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=640
http://xforce.iss.net/xforce/xfdb/39707
http://securitytracker.com/id?1019193
http://secunia.com/advisories/28490

Copyright 2020, cxsecurity.com

 

Back to Top