2 results (0.005 seconds)

CVSS: 5.0EPSS: 0%CPEs: 50EXPL: 0

TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0; TIBCO BusinessEvents Runtime in Enterprise and Inference Editions 3.x before 3.0.3, Standard Edition 4.x before 4.0.2, and Standard Edition and Express 5.0.0; and TIBCO BusinessWorks Engine in TIBCO Silver Fabric ActiveMatrix BusinessWorks Distribution 5.9.2 and ActiveMatrix BusinessWorks before 5.9.3 allow remote attackers to obtain sensitive information via a crafted URL. TIBCO ActiveMatrix Runtime Platform de Service Grid y Service Bus 2.x anteriores a 2.3.2 y BusinessWorks Service Engine anteriores a 5.8.2; TIBCO ActiveMatrix Platform de TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid y Service Bus 3.x anteriores a 3.1.5, BusinessWorks Service Engine 5.9.x anteriores a 5.9.3, y BPM anteriores a 1.3.0; TIBCO BusinessEvents Runtime de Enterprise y Inference Editions 3.x anteriores a 3.0.3, Standard Edition 4.x anteriores a 4.0.2, y Standard Edition y Express 5.0.0; y TIBCO BusinessWorks Engine de TIBCO Silver Fabric ActiveMatrix BusinessWorks Distribution 5.9.2 y ActiveMatrix BusinessWorks anteriores a 5.9.3 permiten a atacantes remotos obtener información confidencial a través de una URL modificada. • http://www.tibco.com/multimedia/activematrix2_advisory_20120308_tcm8-15726.txt http://www.tibco.com/multimedia/activematrix3_advisory_20120308_tcm8-15728.txt http://www.tibco.com/multimedia/businessevents_advisory_20120308_tcm8-15729.txt http://www.tibco.com/multimedia/businessworks_advisory_20120308_tcm8-15730.txt http://www.tibco.com/services/support/advisories/amx-be-spotfire-advisory_20120308.jsp • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 9%CPEs: 4EXPL: 0

The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors. Los componentes (1) ActiveMatrix Runtime y(2) ActiveMatrix Administrator en TIBCO ActiveMatrix Service Grid anterior v2.3.1, ActiveMatrix Service Bus anterior v2.3.1, ActiveMatrix BusinessWorks Service Engine anterior v5.8.1, y ActiveMatrix Service Performance Manager anterior v1.3.2 no maneja adecuadamente las conexiones JMX, lo que permite a atacantes remotos ejecutar código de su elección, obtener información sensible, o causar una denegación de servicio a través de vectores no especificados. • http://secunia.com/advisories/41891 http://www.securityfocus.com/bid/44254 http://www.tibco.com/multimedia/activematrix_advisory_tcm8-12488.txt http://www.tibco.com/services/support/advisories/activematrix-advisory_20101019.jsp http://www.vupen.com/english/advisories/2010/2747 https://exchange.xforce.ibmcloud.com/vulnerabilities/62674 • CWE-20: Improper Input Validation •