Vulnerability Description
The Ice Faces servlet in ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows remote attackers to upload and execute arbitrary Java code via a crafted XML document.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tibbo | Aggregate | <= 5.21.02 |
References
- http://zerodayinitiative.com/advisories/ZDI-15-571/
- https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01PatchUS Government Resource
- http://zerodayinitiative.com/advisories/ZDI-15-571/
- https://ics-cert.us-cert.gov/advisories/ICSA-15-323-01PatchUS Government Resource
FAQ
What is CVE-2015-7912?
CVE-2015-7912 is a vulnerability with a CVSS score of 10.0 (HIGH). The Ice Faces servlet in ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows remote attackers to upload and execute arbitrary Java code via a crafted XML doc...
How severe is CVE-2015-7912?
CVE-2015-7912 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7912?
Check the references section above for vendor advisories and patch information. Affected products include: Tibbo Aggregate.