HTTP: IBM Rational Rhapsody BB FlashBack FBRecorder Multiple ActiveX

This signature detects attempts to use unsafe ActiveX controls in IBM Rational Rhapsody. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

BB Flashback is prone to multiple remote code-execution vulnerabilities. Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. BB Flashback versions prior to 2.0.0.214 are vulnerable.

Affected Products

Ibm rational_rhapsody

References

BugTraq: 51184

CVE: CVE-2011-1388

Short Name
HTTP:STC:ACTIVEX:IBM-RATIONAL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX BB CVE-2011-1388 CVE-2011-1391 FBRecorder FlashBack IBM Multiple Rational Rhapsody bid:51184
Release Date
02/02/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Ibm

Blueberry_software

CVSS Score

9.3

Found a potential security threat?