CVE-2011-0649
Summary
| CVE | CVE-2011-0649 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-04 01:00:08 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknown vectors related to SUID and (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd). |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Enterprise Message Service | 5.1.0 | All | All | All |
| Application | Tibco | Enterprise Message Service | 5.1.1 | All | All | All |
| Application | Tibco | Enterprise Message Service | 6.0.0 | All | All | All |
| Application | Tibco | Rendezvous | 8.2.1 | All | All | All |
| Application | Tibco | Rendezvous | 8.3.0 | All | All | All |
| Application | Tibco | Runtime Agent | 5.6.2 | All | All | All |
| Application | Tibco | Runtime Agent | 5.7.0 | All | All | All |
| Application | Tibco | Silver Bpm Service | 1.0.1 | All | All | All |
| Application | Tibco | Silver Bpm Service | All | All | All | All |
| Application | Tibco | Silver Businessworks Service | 1.0.0 | All | All | All |
| Application | Tibco | Silver Cap Service | 1.0.0 | All | All | All |
| Application | Tibco | Silver Cap Service | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TIBCO Enterprise Message Service Unspecified Privilege Escalation Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Multiple TIBCO Products Unspecified Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.tibco.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| TIBCO Rendezvous Unspecified Privilege Escalation Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.