CVE-2007-5657
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.55% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- tibco/rtworks · tibco/smartsockets rtserver · tibco/enterprise message service
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=640
- http://secunia.com/advisories/28490
- http://securitytracker.com/id?1019193
- http://www.securityfocus.com/bid/27295
- http://www.tibco.com/mk/advisory.jsp
- http://www.tibco.com/resources/mk/ems_security_advisory_20080115.txt
- http://www.tibco.com/resources/mk/smartsockets_security_advisory_20080115.txt
- http://www.tibco.com/resources/mk/sspfm_security_advisory_20080115.txt
- http://www.vupen.com/english/advisories/2008/0173
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39707
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=640
- http://secunia.com/advisories/28490
- http://securitytracker.com/id?1019193
- http://www.securityfocus.com/bid/27295
- http://www.tibco.com/mk/advisory.jsp
- http://www.tibco.com/resources/mk/ems_security_advisory_20080115.txt
- http://www.tibco.com/resources/mk/smartsockets_security_advisory_20080115.txt
- http://www.tibco.com/resources/mk/sspfm_security_advisory_20080115.txt
- http://www.vupen.com/english/advisories/2008/0173
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39707
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.