« Volver al listado

CVE-2008-1704

Estado: ModificadaAlta (10)—

Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow remote attackers to execute arbitrary code via a crafted message to the EMS server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1704",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-04-11T10:05:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/29775",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/28717",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1019826",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.tibco.com/resources/mk/ems_security_advisory_20080409.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1190/references",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41761",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29775",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/28717",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1019826",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.tibco.com/resources/mk/ems_security_advisory_20080409.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1190/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41761",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow remote attackers to execute arbitrary code via a crafted message to the EMS server."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de bufer en TIBCO Software Enterprise Message Service (EMS) anterior a 4.4.3, y iProcess Engine 10.6.0 a 10.6.1, permite a atacantes remotos ejecutar código de su elección mediante un mensaje manipulado a el servidor EMS."
    }
  ],
  "lastModified": "2026-06-16T22:52:19.760",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tibco:enterprise_message_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "457287F0-58ED-4F7E-8A16-6F757262CD62",
              "versionEndIncluding": "4.4.2"
            },
            {
              "criteria": "cpe:2.3:a:tibco:enterprise_message_service:4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A391F64-B618-4961-942C-109CE548FBB9"
            },
            {
              "criteria": "cpe:2.3:a:tibco:enterprise_message_service:4.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3811EEE8-ED90-4272-BDC9-9FBB7E2ABC50"
            },
            {
              "criteria": "cpe:2.3:a:tibco:enterprise_message_service:4.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72D4BFCE-FD9B-45D8-B23A-B928B86ED2B8"
            },
            {
              "criteria": "cpe:2.3:a:tibco:enterprise_message_service:4.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8B14826-B53E-46DC-8AE9-85776867D341"
            },
            {
              "criteria": "cpe:2.3:a:tibco:enterprise_message_service:4.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A42A8728-2B49-4F1F-930C-AB2B808BDDA0"
            },
            {
              "criteria": "cpe:2.3:a:tibco:enterprise_message_service:4.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50598050-FAC6-42B6-98E5-D02DF85F1A07"
            },
            {
              "criteria": "cpe:2.3:a:tibco:iprocess_engine:10.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF6D5769-8FE2-4923-94EE-92619D8D086A"
            },
            {
              "criteria": "cpe:2.3:a:tibco:iprocess_engine:10.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C65C714C-91B8-4665-B9BD-699BE318EDA2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}