VulnerabilityModified
CVE-2012-5302
The server in TIBCO Formvine 3.1.x and 3.2.x before 3.2.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
HIGH 7.5EPSS 2.36%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The server in TIBCO Formvine 3.1.x and 3.2.x before 3.2.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.36% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- tibco/formvine
- Source
- cve@mitre.org
References
- http://osvdb.org/86606
- http://www.securityfocus.com/bid/56225
- http://www.tibco.com/multimedia/formvine-advisory-2012-10-23_tcm8-17451.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/formvine-advisory_20121023.jspVendor Advisory
- http://osvdb.org/86606
- http://www.securityfocus.com/bid/56225
- http://www.tibco.com/multimedia/formvine-advisory-2012-10-23_tcm8-17451.txtVendor Advisory
- http://www.tibco.com/services/support/advisories/formvine-advisory_20121023.jspVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.