CVE-2015-7913
ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Affected
- tibbo/aggregate
- Source
- ics-cert@hq.dhs.gov
References
- http://zerodayinitiative.com/advisories/ZDI-15-572/
- https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01Patch, US Government Resource
- http://zerodayinitiative.com/advisories/ZDI-15-572/
- https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01Patch, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.