Vulnerability Name:

CVE-2011-1207 (CCN-66885)

Assigned:2011-04-25
Published:2011-04-25
Updated:2023-05-30
Summary:
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2011-1207

Source: CCN
Type: SA43399
IBM Rational System Architect ActiveBar ActiveX Control Vulnerabilities

Source: CCN
Type: SA43474
Data Dynamics ActiveBar ActiveX Control SetLayoutData() Vulnerability

Source: CCN
Type: SA44456
Legacy Family Tree ActiveBar ActiveX Control Vulnerabilities

Source: cve@mitre.org
Type: Third Party Advisory, VDB Entry
cve@mitre.org

Source: CCN
Type: Legacy Family Tree Website
Legacy Family Tree

Source: CCN
Type: Microsoft Security Advisory (2562937)
Update Rollup for ActiveX Kill Bits

Source: CCN
Type: OSVDB ID: 72136
Data Dynamics ActiveBar ActiveBar1 ActiveX SetLayoutData() Method Data Argument Arbitrary Code Execution

Source: CCN
Type: BID-47643
Data Dynamics ActiveBar ActiveX Control Insecure Method Vulnerability

Source: cve@mitre.org
Type: Third Party Advisory, VDB Entry
cve@mitre.org

Source: cve@mitre.org
Type: Vendor Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
rational-architect-activebar-ce(66885)

Source: CCN
Type: IBM Security Alert
Rational System Architect ActiveBar ActiveX Control Vulnerabilities

Source: cve@mitre.org
Type: Patch, Vendor Advisory
cve@mitre.org

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:ibm:rational_system_architect:11.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_system_architect:11.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_system_architect:11.3.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_system_architect:11.3.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_system_architect:11.3.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_system_architect:11.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_system_architect:11.4.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_system_architect:11.4.0.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows:server_2003:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:server_2003:sp2:itanium:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:server_2003:sp2:x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_xp::sp2:x64:*:professional:*:*:*
  • OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows:xp:sp3:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_vista:-:sp2:x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*
  • OR cpe:/o:microsoft:windows_7:-:*:*:*:*:*:x32:*
  • OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*
  • OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x64:*
  • OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*

  • * Denotes that component is vulnerable
    BACK
    ibm rational system architect 11.3
    ibm rational system architect 11.3.1
    ibm rational system architect 11.3.1.1
    ibm rational system architect 11.3.1.2
    ibm rational system architect 11.3.1.3
    ibm rational system architect 11.4
    ibm rational system architect 11.4.0.1
    ibm rational system architect 11.4.0.2
    microsoft windows server_2003 sp2
    microsoft windows server_2003 sp2
    microsoft windows server_2003 sp2
    microsoft windows xp sp2
    microsoft windows server 2008 -
    microsoft windows xp sp3
    microsoft windows vista - sp2
    microsoft windows vista - sp2
    microsoft windows server 2008 sp2
    microsoft windows 7 -
    microsoft windows server 2008 - r2
    microsoft windows server 2008 r2
    microsoft windows server 2008
    microsoft windows 7 - sp1
    microsoft windows server 2008 r2 sp1
    microsoft windows server 2008 r2 sp1