First published: Wed Apr 20 2016(Updated: )
Buffer overflow in tibemsd in the server in TIBCO Enterprise Message Service (EMS) before 8.3.0 and EMS Appliance before 2.4.0 allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via crafted inbound data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tibco Enterprise Message Service Appliance | ||
Tibco Enterprise Message Service Appliance Firmware | <=2.3.1 | |
TIBCO Enterprise Message Service | <=8.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3628 has a severity level that may lead to denial of service and potential arbitrary code execution.
To fix CVE-2016-3628, upgrade TIBCO Enterprise Message Service to version 8.3.0 or later and TIBCO EMS Appliance to version 2.4.0 or later.
CVE-2016-3628 affects TIBCO Enterprise Message Service versions up to 8.2.2 and TIBCO EMS Appliance Firmware versions up to 2.3.1.
Yes, CVE-2016-3628 is exploitable by remote authenticated users who send crafted inbound data.
The potential impacts of CVE-2016-3628 include service interruption and the possibility of executing arbitrary code.