Lucene search

K
cve[email protected]CVE-2010-0184
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-0184

2022-10-0316:21:11
CWE-264
web.nvd.nist.gov
18
tibco
domain utility
tra
weak permissions
vulnerability
cve-2010-0184

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.

Affected configurations

NVD
Node
tibcoruntime_agentRange5.6.1
OR
tibcoruntime_agentMatch5.4.0
OR
tibcoruntime_agentMatch5.5.3
OR
tibcoruntime_agentMatch5.5.4
OR
tibcoruntime_agentMatch5.6

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2010-0184