Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-0649


Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknown vectors related to SUID and (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd).


Published

2011-02-04T01:00:08.323

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tibco rendezvous 8.2.1 Yes
Application tibco rendezvous 8.3.0 Yes
Application tibco enterprise_message_service 5.1.0 Yes
Application tibco enterprise_message_service 5.1.1 Yes
Application tibco enterprise_message_service 6.0.0 Yes
Application tibco runtime_agent 5.6.2 Yes
Application tibco runtime_agent 5.7.0 Yes
Application tibco silver_bpm_service ≤ 1.0.3 Yes
Application tibco silver_bpm_service 1.0.1 Yes
Application tibco silver_cap_service ≤ 1.0.1 Yes
Application tibco silver_cap_service 1.0.0 Yes
Application tibco silver_businessworks_service 1.0.0 Yes

References