9.3

CVE-2011-1207

The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earlier, does not properly restrict the SetLayoutData method, which allows remote attackers to execute arbitrary code via a crafted Data argument, a different vulnerability than CVE-2007-3883.  NOTE: some of these details are obtained from third party information.

Data is provided by the National Vulnerability Database (NVD)
IbmRational System Architect Version <= 11.4.0.2
IbmRational System Architect Version11.3
IbmRational System Architect Version11.3.1
IbmRational System Architect Version11.3.1.1
IbmRational System Architect Version11.3.1.2
IbmRational System Architect Version11.3.1.3
IbmRational System Architect Version11.4
IbmRational System Architect Version11.4.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.45% 0.88
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.