2024-04-04 08:46:00 +00:00

125 lines
4.0 KiB
JSON

{
"id": "CVE-2010-0184",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-01-14T19:30:00.483",
"lastModified": "2011-08-08T04:00:00.000",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors."
},
{
"lang": "es",
"value": "Los componentes (1)domainutility y (2)domainutilitycmd en TIBCO Domain Utility en TIBCO Runtime Agent (TRA) anterior a v5.6.2, usado en TIBCO ActiveMatrix BusinessWorks y otros productos, establece permisos d\u00e9biles sobre los archivos de propiedades del dominio, lo que permite a usuarios locales, obtener credenciales de administrador, y obtener privilegios sobre todos lo sistemas, a trav\u00e9s de vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.2
},
"baseSeverity": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tibco:runtime_agent:*:*:*:*:*:*:*:*",
"versionEndIncluding": "5.6.1",
"matchCriteriaId": "DB0D5A21-4A21-4DFF-9549-109039252387"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tibco:runtime_agent:5.4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0A6C4A47-FBEF-4171-9C97-FFAD45ACB263"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tibco:runtime_agent:5.5.3:*:*:*:*:*:*:*",
"matchCriteriaId": "19E9CA44-31F3-48B2-834A-36F792A71761"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tibco:runtime_agent:5.5.4:*:*:*:*:*:*:*",
"matchCriteriaId": "A60DB3FE-F502-4A8E-A669-3837109A2211"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tibco:runtime_agent:5.6:*:*:*:*:*:*:*",
"matchCriteriaId": "DCE75BE6-19FE-442D-80C1-87003D62786C"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/38191",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/37805",
"source": "cve@mitre.org"
},
{
"url": "http://www.tibco.com/mk/advisory.jsp",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.tibco.com/multimedia/security_advisory_runtime_agent_20100113_tcm8-10392.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/0128",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}