CVE-2010-3491
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.55% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- tibco/activematrix businessworks service engine · tibco/activematrix service bus · tibco/activematrix service grid · tibco/activematrix service performance manager
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/41891Vendor Advisory
- http://www.securityfocus.com/bid/44254
- http://www.tibco.com/multimedia/activematrix_advisory_tcm8-12488.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/activematrix-advisory_20101019.jspPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2747Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62674
- http://secunia.com/advisories/41891Vendor Advisory
- http://www.securityfocus.com/bid/44254
- http://www.tibco.com/multimedia/activematrix_advisory_tcm8-12488.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/activematrix-advisory_20101019.jspPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2747Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62674
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.