CVE-2006-2829
Summary
| CVE | CVE-2006-2829 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-05 20:06:00 UTC |
| Updated | 2017-07-20 01:31:00 UTC |
| Description | Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Hawk | 4.6.0 | All | All | All |
| Application | Tibco | Hawk | 4.6.0 | All | All | All |
| Application | Tibco | Hawk Monitoring Agent | All | All | All | All |
| Application | Tibco | Hawk Monitoring Agent | All | All | All | All |
| Application | Tibco | Runtime Agent | 5.3 | All | All | All |
| Application | Tibco | Runtime Agent | 5.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| TIBCO Hawk Configuration Interface Local Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| TIBCO Hawk "tibhawkhma" Privilege Escalation Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 404 Not Found | CONFIRM | www.tibco.com | Patch, Vendor Advisory |
| US-CERT Vulnerability Note VU#620516 | CERT-VN | www.kb.cert.org | Patch, US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - TIBCO Hawk Monitoring Agent Buffer Overflow May Let Local Users Gain Elevated Privileges | SECTRACK | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.