CVE-2011-0649
Last modified
CVE-2011-0649 is a vulnerability of currently unknown severity. Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknown vectors related to SUID and (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd).. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknown vectors related to SUID and (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd).
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tibco | Rendezvous | 8.2.1 |
| Tibco | Rendezvous | 8.3.0 |
| Tibco | Enterprise Message Service | 5.1.0 |
| Tibco | Enterprise Message Service | 5.1.1 |
| Tibco | Enterprise Message Service | 6.0.0 |
| Tibco | Runtime Agent | 5.6.2 |
| Tibco | Runtime Agent | 5.7.0 |
| Tibco | Silver Bpm Service | <= 1.0.3 |
| Tibco | Silver Bpm Service | 1.0.1 |
| Tibco | Silver Cap Service | <= 1.0.1 |
| Tibco | Silver Cap Service | 1.0.0 |
| Tibco | Silver Businessworks Service | 1.0.0 |
References
- http://secunia.com/advisories/43160Vendor Advisory
- http://secunia.com/advisories/43174Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0269Vendor Advisory
- http://secunia.com/advisories/43160Vendor Advisory
- http://secunia.com/advisories/43174Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0269Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0649?
How severe is CVE-2011-0649?
How do I fix CVE-2011-0649?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-0643Cross-site request forgery (CSRF) vulnerability in admin/con…
- CVE-2011-0644SQL injection vulnerability in include/admin/model_field.cla…
- CVE-2011-0645SQL injection vulnerability in data.php in PHPCMS 2008 V2 al…
- CVE-2011-0646SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS …
- CVE-2011-0647The irccd.exe service in EMC Replication Manager Client befo…
- CVE-2011-0648Unspecified vulnerability in EMC Avamar before 5.0.4-30 allo…
- CVE-2011-0650Cross-site request forgery (CSRF) vulnerability in Greenbone…
- CVE-2011-0651Buffer overflow in the key exchange functionality in Icon La…
- CVE-2011-0652lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 an…
- CVE-2011-0653Cross-site scripting (XSS) vulnerability in Microsoft Office…
- CVE-2011-0654Integer underflow in the BowserWriteErrorLogEntry function i…
- CVE-2011-0655Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, a…
Are you affected by CVE-2011-0649?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
