Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TIBCO SmartSockets不可信任指针远程代码执行漏洞
Vulnerability Description
TIBCO SmartSockets是用于通过独立通道传输消息的传送框架,RTserver是其中的服务器组件。 SmartSockets在处理请求时使用了来自请求的值作为指针,然后在各种内存操作中用到了所生成的指针值。由于攻击者可以指针值,因此可能触发可利用的情况,导致RTserver拒绝服务或以系统权限执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A