CVE-2015-7913: Tibbo Aggregate

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class.

Affected products

  • Tibbo Aggregate: up to and including 5.21.02

Published 2015-11-21. Last modified 2026-06-17.