Unspecified vulnerability in the ActiveMatrix Runtime component in TIBCO ActiveMatrix Service Grid 3.0.0, 3.0.1, and 3.1.0; ActiveMatrix Service Bus 3.0.0 and 3.0.1; ActiveMatrix BusinessWorks Service Engine 5.9.0; ActiveMatrix BPM 1.0.1 and 1.0.2; Silver BPM Service 1.0.1; and Silver CAP Service 1.0.0 allows remote authenticated users to execute arbitrary code via vectors related to JMX connections.
Conclusion & alert: CVE-2010-4495 is rated Moderate Risk (61.6/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 1.95% | 1.06% | -0.89% |
| 2 | 2025-03-29 | 1.06% | 1.95% | +0.89% |
| 3 | 2025-03-19 | — | 1.06% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 2.0 | HIGH |
|
8.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tibco | activematrix_bpm | 1.0.1 | cpe:2.3:a:tibco:activematrix_bpm:1.0.1:*:*:*:*:*:*:* |
| tibco | activematrix_bpm | 1.0.2 | cpe:2.3:a:tibco:activematrix_bpm:1.0.2:*:*:*:*:*:*:* |
| tibco | activematrix_businessworks_service_engine | 5.9.0 | cpe:2.3:a:tibco:activematrix_businessworks_service_engine:5.9.0:*:*:*:*:*:*:* |
| tibco | activematrix_service_bus | 3.0.0 | cpe:2.3:a:tibco:activematrix_service_bus:3.0.0:*:*:*:*:*:*:* |
| tibco | activematrix_service_bus | 3.0.1 | cpe:2.3:a:tibco:activematrix_service_bus:3.0.1:*:*:*:*:*:*:* |
| tibco | activematrix_service_grid | 3.0.0 | cpe:2.3:a:tibco:activematrix_service_grid:3.0.0:*:*:*:*:*:*:* |
| tibco | activematrix_service_grid | 3.0.1 | cpe:2.3:a:tibco:activematrix_service_grid:3.0.1:*:*:*:*:*:*:* |
| tibco | activematrix_service_grid | 3.1.0 | cpe:2.3:a:tibco:activematrix_service_grid:3.1.0:*:*:*:*:*:*:* |
| tibco | silver_bpm_service | 1.0.1 | cpe:2.3:a:tibco:silver_bpm_service:1.0.1:*:*:*:*:*:*:* |
| tibco | silver_cap_service | 1.0.0 | cpe:2.3:a:tibco:silver_cap_service:1.0.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://secunia.com/advisories/42640 | Vendor Advisory |
| http://www.securityfocus.com/bid/45400 | |
| http://www.securitytracker.com/id?1024894 | |
| http://www.tibco.com/multimedia/activematrix_advisory_20101214_tcm8-12728.txt | Vendor Advisory |
| http://www.vupen.com/english/advisories/2010/3241 | Vendor Advisory |