CVE-2010-0184Runtime Agent vulnerability

CWE-2645 documents5 sources
Severity
7.2HIGHNVD
EPSS
0.0%
top 90.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 14
Latest updateMay 2

Description

The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDtibco/runtime_agent5.6.1+4

🔴Vulnerability Details

2
GHSA
GHSA-f23h-24h4-f4x9: The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 52022-05-02
CVEList
CVE-2010-0184: The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 52010-01-14

💥Exploits & PoCs

1
Exploit-DB
Free Download Manager 3.0 Build 844 - Torrent Parsing Buffer Overflow (Metasploit)2010-09-25

💬Community

1
Bugzilla
CVE-2010-2387 gdm: logs user passwors that contain invalid UTF8-encoded characters, in debug mode2012-12-21
CVE-2010-0184 — Tibco Runtime Agent vulnerability | cvebase