Описание
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.
Ссылки
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.3 (включая)Версия до 6.8.0 (включая)
Одно из
cpe:2.3:a:tibco:rtworks:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:smartsockets_rtserver:*:*:*:*:*:*:*:*
Конфигурация 2
Одновременно
cpe:2.3:h:tibco:ems_server:*:*:*:*:*:*:*:*
cpe:2.3:a:tibco:enterprise_message_service:*:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.0555
Низкий
10 Critical
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
больше 4 лет назад
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.
EPSS
Процентиль: 92%
0.0555
Низкий
10 Critical
CVSS2
Дефекты
CWE-20