Rule

--
Sid
24725

--
Summary:
This event is generated when an attempt is made to exploit a known vulnerability in bb flashback.

--
Impact:
Denial of Service. Information disclosure. Loss of integrity. 

--
Detailed Information:
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the TestCompatibilityRecordMode method, which allows remote attackers to execute arbitrary code via unspecified vectors.

--
Affected Systems:
.bbsoftware bb flashback 

--
Attack Scenarios:


--
Ease of Attack:
Simple. Exploits exist.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:
Upgrade to the latest non-affected version of the software.

Apply the appropriate vendor supplied patches.

--
Contributors:
Sourcefire Vulnerability Research Team
This document was generated from data supplied by the National Vulnerability Database. A product of the National Institute of Standards and Technology.
For more information see http://nvd.nist.gov/

--
Additional References:

NIST CVE-2011-1388:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1388
  
--
