First published: Fri Apr 11 2008(Updated: )
Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow remote attackers to execute arbitrary code via a crafted message to the EMS server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Enterprise Message Service | <=4.4.2 | |
TIBCO iProcess Engine | =10.6.0 | |
TIBCO Enterprise Message Service | =4.4.1 | |
TIBCO Enterprise Message Service | =4.4.0 | |
TIBCO Enterprise Message Service | =4.1.0 | |
TIBCO Enterprise Message Service | =4.2.0 | |
TIBCO Enterprise Message Service | =4.0.0 | |
TIBCO Enterprise Message Service | =4.3.0 | |
TIBCO iProcess Engine | =10.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1704 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2008-1704, upgrade to TIBCO Enterprise Message Service version 4.4.3 or later, or TIBCO iProcess Engine version 10.6.2 or later.
CVE-2008-1704 affects TIBCO Software Enterprise Message Service versions before 4.4.3 and iProcess Engine versions 10.6.0 through 10.6.1.
CVE-2008-1704 allows remote attackers to execute arbitrary code by sending a crafted message to the EMS server.
There are no official workarounds available for CVE-2008-1704; updating to a secure version is the recommended mitigation.