Lucene search

K
cveMitreCVE-2002-0941
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2002-0941

2003-04-0205:00:00
mitre
web.nvd.nist.gov
29
vulnerability
ncipher
consolecallback
jre 1.4.0
security
privilege escalation

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

20.3%

The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges.

Affected configurations

Nvd
Node
nciphernforce
Node
nciphernshield
VendorProductVersionCPE
nciphernforce*cpe:2.3:a:ncipher:nforce:*:*:*:*:*:*:*:*
nciphernshield*cpe:2.3:h:ncipher:nshield:*:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

20.3%

Related for CVE-2002-0941