TIBCO Rendezvous Rvrd.DB Information Disclosure Vulnerability
BID:19883
CVE-2006-4676 |Info
TIBCO Rendezvous Rvrd.DB Information Disclosure Vulnerability
| Bugtraq ID: | 19883 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2006 12:00AM |
| Updated: | Sep 07 2006 10:33PM |
| Credit: | Andres Tarasco Acuña has been credited with the discovery of this vulnerability |
| Vulnerable: |
TIBCO Rendezvous 7.4.11 |
| Not Vulnerable: | |
Discussion
TIBCO Rendezvous Rvrd.DB Information Disclosure Vulnerability
TIBCO Rendezvous is prone to a local information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.
An attacker can exploit this issue by gaining access to a world-readable file and extracting authentication credentials from it. Such information could aid in other attacks.
The Windows version of TIBCO Rendezvous version 7.4.11 is vulnerable to this issue; previous versions and other platforms may also be affected.
TIBCO Rendezvous is prone to a local information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.
An attacker can exploit this issue by gaining access to a world-readable file and extracting authentication credentials from it. Such information could aid in other attacks.
The Windows version of TIBCO Rendezvous version 7.4.11 is vulnerable to this issue; previous versions and other platforms may also be affected.
Exploit / POC
TIBCO Rendezvous Rvrd.DB Information Disclosure Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
TIBCO Rendezvous Rvrd.DB Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
TIBCO Rendezvous Rvrd.DB Information Disclosure Vulnerability
References:
References:
- TIBCO Homepage (TIBCO)
- TIBCO Password Extractor (Andres Tarasco Acuña )
- TIBCO Rendezvous Home Page (TIBCO)