First published: Fri Aug 03 2007(Updated: )
index.html in the HTTP administration interface in certain daemons in TIBCO Rendezvous (RV) 7.5.2 allows remote attackers to obtain sensitive information, such as a user name and IP addresses, via a direct request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Rendezvous | =7.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4159 is considered a medium-severity vulnerability as it allows remote attackers to access sensitive information.
To mitigate CVE-2007-4159, it is recommended to restrict access to the HTTP administration interface and update to the latest version of TIBCO Rendezvous.
CVE-2007-4159 can expose sensitive information such as usernames and IP addresses of the users.
CVE-2007-4159 affects TIBCO Rendezvous version 7.5.2.
Attackers can exploit CVE-2007-4159 by directly requesting the index.html page of the affected TIBCO Rendezvous HTTP administration interface.