Lucene search

K
cveMitreCVE-2009-1291
HistoryApr 30, 2009 - 8:30 p.m.

CVE-2009-1291

2009-04-3020:30:00
CWE-119
mitre
web.nvd.nist.gov
42
cve-2009-1291
tibco
smartsockets
rtworks
enterprise message service
ems
buffer overflow
remote code execution

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.6

Confidence

Low

EPSS

0.164

Percentile

96.0%

Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and components, EMS Server (aka tibemsd), SmartMQ, iProcess Engine, ActiveMatrix products, and CA Enterprise Communicator, allows remote attackers to execute arbitrary code via “inbound data,” as demonstrated by requests to the UDP interface of the RTserver component, and data injection into the TCP stream to tibemsd.

Affected configurations

Nvd
Node
tibcoenterprise_message_serviceRange5.1.1
OR
tibcoenterprise_message_serviceMatch4.0.0
OR
tibcoenterprise_message_serviceMatch4.1.0
OR
tibcoenterprise_message_serviceMatch4.2.0
OR
tibcoenterprise_message_serviceMatch4.3.0
OR
tibcoenterprise_message_serviceMatch4.4.1
OR
tibcoenterprise_message_serviceMatch4.4.2
OR
tibcortworksMatch4.0.3
OR
tibcortworksMatch4.0.4
OR
tibcosmartsocketsMatch6.8.0
OR
tibcosmartsocketsMatch6.8.1
OR
tibcosmartsockets_rtserverRange6.8.1
OR
tibcosmartsockets_rtserverMatch6.8.0
VendorProductVersionCPE
tibcoenterprise_message_service*cpe:2.3:a:tibco:enterprise_message_service:*:*:*:*:*:*:*:*
tibcoenterprise_message_service4.0.0cpe:2.3:a:tibco:enterprise_message_service:4.0.0:*:*:*:*:*:*:*
tibcoenterprise_message_service4.1.0cpe:2.3:a:tibco:enterprise_message_service:4.1.0:*:*:*:*:*:*:*
tibcoenterprise_message_service4.2.0cpe:2.3:a:tibco:enterprise_message_service:4.2.0:*:*:*:*:*:*:*
tibcoenterprise_message_service4.3.0cpe:2.3:a:tibco:enterprise_message_service:4.3.0:*:*:*:*:*:*:*
tibcoenterprise_message_service4.4.1cpe:2.3:a:tibco:enterprise_message_service:4.4.1:*:*:*:*:*:*:*
tibcoenterprise_message_service4.4.2cpe:2.3:a:tibco:enterprise_message_service:4.4.2:*:*:*:*:*:*:*
tibcortworks4.0.3cpe:2.3:a:tibco:rtworks:4.0.3:*:*:*:*:*:*:*
tibcortworks4.0.4cpe:2.3:a:tibco:rtworks:4.0.4:*:*:*:*:*:*:*
tibcosmartsockets6.8.0cpe:2.3:a:tibco:smartsockets:6.8.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.6

Confidence

Low

EPSS

0.164

Percentile

96.0%

Related for CVE-2009-1291