CVE-2007-5545
Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.54% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-134
- Affected
- tibco/smart pgm fx
- Source
- cve@mitre.org
References
- http://osvdb.org/45276
- http://securityreason.com/securityalert/3249
- http://www.irmplc.com/index.php/111-Vendor-Alerts
- http://www.securityfocus.com/archive/1/482353/100/0/threaded
- http://www.securityfocus.com/bid/26092
- http://osvdb.org/45276
- http://securityreason.com/securityalert/3249
- http://www.irmplc.com/index.php/111-Vendor-Alerts
- http://www.securityfocus.com/archive/1/482353/100/0/threaded
- http://www.securityfocus.com/bid/26092
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.