CVE-2010-3491
Last modified
CVE-2010-3491 is a vulnerability of currently unknown severity. The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.. EPSS estimates a 4.55% chance of exploitation in the next 30 days.
Description
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tibco | Activematrix Businessworks Service Engine | <= 5.8.0 |
| Tibco | Activematrix Service Bus | <= 2.3.0 |
| Tibco | Activematrix Service Grid | <= 2.3.0 |
| Tibco | Activematrix Service Performance Manager | <= 1.3.1 |
References
- http://secunia.com/advisories/41891Vendor Advisory
- http://www.tibco.com/services/support/advisories/activematrix-advisory_20101019.jspPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2747Vendor Advisory
- http://secunia.com/advisories/41891Vendor Advisory
- http://www.tibco.com/services/support/advisories/activematrix-advisory_20101019.jspPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2747Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3491?
How severe is CVE-2010-3491?
How do I fix CVE-2010-3491?
Are you affected by CVE-2010-3491?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
