CVE-2011-0649
Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknown vectors related to SUID and (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd).
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Affected
- tibco/rendezvous · tibco/enterprise message service · tibco/runtime agent · tibco/silver bpm service · tibco/silver cap service · tibco/silver businessworks service
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/43160Vendor Advisory
- http://secunia.com/advisories/43174Vendor Advisory
- http://www.securityfocus.com/bid/46104
- http://www.tibco.com/multimedia/rv_ems_security_advisory_20110201_tcm8-13185.txtVendor Advisory
- http://www.vupen.com/english/advisories/2011/0269Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65105
- http://secunia.com/advisories/43160Vendor Advisory
- http://secunia.com/advisories/43174Vendor Advisory
- http://www.securityfocus.com/bid/46104
- http://www.tibco.com/multimedia/rv_ems_security_advisory_20110201_tcm8-13185.txtVendor Advisory
- http://www.vupen.com/english/advisories/2011/0269Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65105
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.