Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:ACTIVEX:IBM-RATIONAL

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

IBM Rational Rhapsody BB FlashBack FBRecorder Multiple ActiveX

Release Date

2012/02/02

Update Number

2075

Supported Platforms

idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: IBM Rational Rhapsody BB FlashBack FBRecorder Multiple ActiveX


This signature detects attempts to use unsafe ActiveX controls in IBM Rational Rhapsody. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

BB Flashback is prone to multiple remote code-execution vulnerabilities. Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. BB Flashback versions prior to 2.0.0.214 are vulnerable.

Affected Products

  • Blueberry Software BB FlashBack SDK
  • IBM Rational Rhapsody 7.5
  • IBM Rational Rhapsody 7.5.1
  • IBM Rational Rhapsody 7.5.2
  • IBM Rational Rhapsody 7.6

References

  • BugTraq: 51184
  • CVE: CVE-2011-1388

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out