Impact
The flaw arises from a configuration issue in Java Management Extensions (JMX) for TIBCO BPM Enterprise 4.x, permitting unauthorised access without authentication. This weakness (CWE-306) can enable an attacker to execute arbitrary code on the host, compromising confidentiality, integrity, and availability of the system.
Affected Systems
TIBCO BPM Enterprise 4.x installations are affected. The attack applies to any environment where JMX is enabled and accessible without proper authentication.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker would typically target the JMX interface over the network, exploiting the lack of authentication to gain remote code execution. No public exploit is documented, but the risk remains due to the high impact of potential code execution.
OpenCVE Enrichment