CVE-2010-0184
The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- tibco/runtime agent
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/38191Vendor Advisory
- http://www.securityfocus.com/bid/37805
- http://www.tibco.com/mk/advisory.jspVendor Advisory
- http://www.tibco.com/multimedia/security_advisory_runtime_agent_20100113_tcm8-10392.txt
- http://www.vupen.com/english/advisories/2010/0128Vendor Advisory
- http://secunia.com/advisories/38191Vendor Advisory
- http://www.securityfocus.com/bid/37805
- http://www.tibco.com/mk/advisory.jspVendor Advisory
- http://www.tibco.com/multimedia/security_advisory_runtime_agent_20100113_tcm8-10392.txt
- http://www.vupen.com/english/advisories/2010/0128Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.