CVE-2010-4498
Unspecified vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to modify data or obtain sensitive information via a crafted…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- tibco/activecatalog · tibco/collaborative information manager
- Source
- cve@mitre.org
References
- http://osvdb.org/70373
- http://secunia.com/advisories/42791Vendor Advisory
- http://www.securityfocus.com/bid/45691
- http://www.securitytracker.com/id?1024942
- http://www.tibco.com/multimedia/cim_advisory_20110105_tcm8-12765.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/cim-advisory_20100105.jspVendor Advisory
- http://www.vupen.com/english/advisories/2011/0037Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64522
- http://osvdb.org/70373
- http://secunia.com/advisories/42791Vendor Advisory
- http://www.securityfocus.com/bid/45691
- http://www.securitytracker.com/id?1024942
- http://www.tibco.com/multimedia/cim_advisory_20110105_tcm8-12765.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/cim-advisory_20100105.jspVendor Advisory
- http://www.vupen.com/english/advisories/2011/0037Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64522
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.