- Description
- TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-119
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:rtworks:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A4F1058-6D26-4FA9-ACC0-8E2CB9E47EE8",
"versionEndIncluding": "4.0.3"
},
{
"criteria": "cpe:2.3:a:tibco:smartsockets_rtserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A607554-6A94-47FC-919C-8BC77E72E527",
"versionEndIncluding": "6.8.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tibco:ems_server:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A71A6DEC-C0A5-456D-BB28-EC5CA61BE796"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:enterprise_message_service:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C559EFC8-9BA6-41F7-AB44-3C10AEC52F56"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]