CVE-2010-3491
Last modified
CVE-2010-3491 is a vulnerability of currently unknown severity. The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.. EPSS estimates a 4.55% chance of exploitation in the next 30 days.
Description
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tibco | Activematrix Businessworks Service Engine | <= 5.8.0 |
| Tibco | Activematrix Service Bus | <= 2.3.0 |
| Tibco | Activematrix Service Grid | <= 2.3.0 |
| Tibco | Activematrix Service Performance Manager | <= 1.3.1 |
References
- http://secunia.com/advisories/41891Vendor Advisory
- http://www.tibco.com/services/support/advisories/activematrix-advisory_20101019.jspPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2747Vendor Advisory
- http://secunia.com/advisories/41891Vendor Advisory
- http://www.tibco.com/services/support/advisories/activematrix-advisory_20101019.jspPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2747Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3491?
How severe is CVE-2010-3491?
How do I fix CVE-2010-3491?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3485SQL injection vulnerability in common.php in LightNEasy 3.2.…
- CVE-2010-3486Directory traversal vulnerability in FileStorageUpload.ashx …
- CVE-2010-3487Directory traversal vulnerability in YelloSoft Pinky 1.0 for…
- CVE-2010-3488Directory traversal vulnerability in QuickShare 1.0 allows r…
- CVE-2010-3489Cross-site scripting (XSS) vulnerability in netautor/napro4/…
- CVE-2010-3490Directory traversal vulnerability in page.recordings.php in …
- CVE-2010-3492The asyncore module in Python before 3.2 does not properly h…
- CVE-2010-3493Multiple race conditions in smtpd.py in the smtpd module in …
- CVE-2010-3494Race condition in the FTPHandler class in ftpserver.py in py…
- CVE-2010-3495Race condition in ZEO/StorageServer.py in Zope Object Databa…
- CVE-2010-3496McAfee VirusScan Enterprise 8.5i and 8.7i does not properly …
- CVE-2010-3497Symantec Norton AntiVirus 2011 does not properly interact wi…
Are you affected by CVE-2010-3491?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
