CVE-2016-3628
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
Buffer overflow in tibemsd in the server in TIBCO Enterprise Message Service (EMS) before 8.3.0 and EMS Appliance before 2.4.0 allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via crafted inbound data.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.tibco.com/mk/advisory.jsp
Vendor advisory: cve@mitre.org — http://www.tibco.com/assets/blt8a2d9978616c21fe/2016-001-advisory.txt
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| tibco | enterprise_message_service_appliance_firmware | {"endIncluding":"2.3.1"} | |
| tibco | enterprise_message_service | {"endIncluding":"8.2.2"} | |
References
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.