TIBCO Runtime Agent Domain Properties Insecure File Permissions Vulnerability
BID:37805
Info
TIBCO Runtime Agent Domain Properties Insecure File Permissions Vulnerability
| Bugtraq ID: | 37805 |
| Class: | Design Error |
| CVE: |
CVE-2007-5655 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 13 2010 12:00AM |
| Updated: | Jan 14 2010 03:41PM |
| Credit: | TIBCO |
| Vulnerable: |
TIBCO Runtime Agent (TRA) 5.6 TIBCO Runtime Agent (TRA) 5.5.4 TIBCO Runtime Agent (TRA) 5.5.3 |
| Not Vulnerable: |
TIBCO Runtime Agent (TRA) 5.6.2 |
Discussion
TIBCO Runtime Agent Domain Properties Insecure File Permissions Vulnerability
TIBCO Runtime Agent is prone to an insecure-file-permissions vulnerability.
Attackers can exploit this issue to gain access to TIBCO domain administrator credentials and execute arbitrary code on systems that are participants in the TIBCO domain.
The issue affects versions prior to TIBCO Runtime Agent 5.6.2.
TIBCO Runtime Agent is prone to an insecure-file-permissions vulnerability.
Attackers can exploit this issue to gain access to TIBCO domain administrator credentials and execute arbitrary code on systems that are participants in the TIBCO domain.
The issue affects versions prior to TIBCO Runtime Agent 5.6.2.
Exploit / POC
TIBCO Runtime Agent Domain Properties Insecure File Permissions Vulnerability
An attacker can use standard tools to exploit this issue.
An attacker can use standard tools to exploit this issue.
Solution / Fix
TIBCO Runtime Agent Domain Properties Insecure File Permissions Vulnerability
Solution:
The vendor has released updates and an advisory. Please see the references for details.
Solution:
The vendor has released updates and an advisory. Please see the references for details.
References
TIBCO Runtime Agent Domain Properties Insecure File Permissions Vulnerability
References:
References:
- TIBCO Homepage (TIBCO)
- TIBCO Runtime Agent vulnerability (TIBCO)