7.2

CVE-2010-0184

The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tibco ≫ Runtime Agent Version <= 5.6.1
Tibco ≫ Runtime Agent Version 5.4.0
Tibco ≫ Runtime Agent Version 5.5.3
Tibco ≫ Runtime Agent Version 5.5.4
Tibco ≫ Runtime Agent Version 5.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.231
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.tibco.com/mk/advisory.jsp
Vendor Advisory
http://secunia.com/advisories/38191
Vendor Advisory
http://www.securityfocus.com/bid/37805
http://www.tibco.com/multimedia/security_advisory_runtime_agent_20100113_tcm8-10392.txt
http://www.vupen.com/english/advisories/2010/0128
Vendor Advisory