TIBCO ActiveMatrix Policy Manager/Agent vulnerabilities

2015.02.22
Credit: tibco
Risk: Low
Local: No
Remote: Yes
CWE: CWE-264


CVSS Base Score: 6.4/10
Impact Subscore: 4.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: None

TIBCO ActiveMatrix Policy Manager/Agent vulnerabilities Original release date: February 18, 2015 Last revised: -- Source: TIBCO Software Inc. Systems Affected TIBCO ActiveMatrix Policy Agent 3.0.0, 3.1.0, 3.1.1 TIBCO ActiveMatrix Policy Manager 3.0.0, 3.1.0, 3.1.1 TIBCO ActiveMatrix Management Agent for WCF 1.0.0, 1.1.0, 1.2.0 TIBCO ActiveMatrix Management Agent for WebSphere 1.0.0, 1.1.0, 1.2.0 The following components are affected: * TIBCO ActiveMatrix Policy Manager Authentication Module Description The TIBCO ActiveMatrix Policy components listed above contain a critical vulnerability which could allow privilege escalation. TIBCO has released updated versions of the affected software products which address these issues. TIBCO strongly recommends sites running the affected components install the applicable update as described below. Impact The impact of this vulnerability may include unprivileged information disclosure. CVSS v2 Base Score: 3.5 (AV:N/AC:L/Au:N/C:P/I:P/A:N) Solution For each affected system, update to the corresponding software versions: TIBCO ActiveMatrix Policy Agent 3.1.2 or higher TIBCO ActiveMatrix Policy Manager 3.1.2 or higher TIBCO ActiveMatrix Management Agent for WCF 1.2.1 or higher TIBCO ActiveMatrix Management Agent for WebSphere 1.2.1 or higher References http://www.tibco.com/mk/advisory.jsp CVE: CVE-2014-5286

References:

http://www.tibco.com/services/support/advisories/activematrix-advisory_20150218
http://www.tibco.com/mk/advisory.jsp
http://www.tibco.com/assets/blt1b18947cad32d1c4/2014-007-advisory.txt


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2022, cxsecurity.com

 

Back to Top