CVE-2013-3315
 
Severity Score
6.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The server in TIBCO Silver Mobile 1.1.0 does not properly verify access to the administrator role before executing a command, which allows authenticated users to gain privileges via unspecified vectors.
El servidor TIBCO Silver Mobile v1.1.0 no verifica de forma adecuada el acceso al rol de administrador antes de ejecutar un comando, lo que permite a usuarios autenticados a aumentar privilegios de a través de vectores no especificados.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-05-01 CVE Reserved
- 2013-05-31 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.tibco.com/multimedia/silver-mobile-advisory-2013-05-08_tcm8-18595.txt | X_refsource_confirm | |
http://www.tibco.com/services/support/advisories/silver-mobile-advisory_20130508.jsp | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.tibco.com/mk/advisory.jsp | 2013-06-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tibco Search vendor "Tibco" | Silver Mobile Search vendor "Tibco" for product "Silver Mobile" | 1.1.0 Search vendor "Tibco" for product "Silver Mobile" and version "1.1.0" | - |
Affected
|