5

CVE-2012-0687

TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0; TIBCO BusinessEvents Runtime in Enterprise and Inference Editions 3.x before 3.0.3, Standard Edition 4.x before 4.0.2, and Standard Edition and Express 5.0.0; and TIBCO BusinessWorks Engine in TIBCO Silver Fabric ActiveMatrix BusinessWorks Distribution 5.9.2 and ActiveMatrix BusinessWorks before 5.9.3 allow remote attackers to obtain sensitive information via a crafted URL.

Data is provided by the National Vulnerability Database (NVD)
TibcoActivematrix Service Bus Version2.0.0
TibcoActivematrix Service Bus Version2.0.1
TibcoActivematrix Service Bus Version2.0.2
TibcoActivematrix Service Bus Version2.1.0
TibcoActivematrix Service Bus Version2.2.0
TibcoActivematrix Service Bus Version2.2.1
TibcoActivematrix Service Bus Version2.3.0
TibcoActivematrix Service Bus Version2.3.1
TibcoActivematrix Service Bus Version3.0.0
TibcoActivematrix Service Bus Version3.0.1
TibcoActivematrix Service Grid Version2.0.0
TibcoActivematrix Service Grid Version2.0.1
TibcoActivematrix Service Grid Version2.1.0
TibcoActivematrix Service Grid Version2.2.0
TibcoActivematrix Service Grid Version2.2.1
TibcoActivematrix Service Grid Version2.3.0
TibcoActivematrix Service Grid Version2.3.1
TibcoActivematrix Service Grid Version2.3.2
TibcoActivematrix Service Grid Version3.0.0
TibcoActivematrix Service Grid Version3.0.1
TibcoActivematrix Service Grid Version3.1.0
TibcoActivematrix Service Grid Version3.1.2
TibcoActivematrix Bpm Version <= 1.2.0
TibcoActivematrix Bpm Version1.0.1
TibcoActivematrix Bpm Version1.0.2
TibcoActivematrix Bpm Version1.1.0
TibcoActivematrix Bpm Version1.1.1
TibcoBusinessevents Version3.0 Editionenterprise
TibcoBusinessevents Version3.0 Editioninference
TibcoBusinessevents Version3.0.1 Editionenterprise
TibcoBusinessevents Version3.0.2 Editionenterprise
TibcoBusinessevents Version3.0.2 Editioninference
TibcoBusinessevents Version4.0 Editionstandard
TibcoBusinessevents Version4.0.1 Editionstandard
TibcoBusinessevents Version5.0 Editionexpress
TibcoBusinessevents Version5.0 Editionstandard
TibcoActivematrix Businessworks Version <= 5.9.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.569
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.