Lucene search

K
cveIbmCVE-2014-0886
HistoryMar 25, 2014 - 8:55 p.m.

CVE-2014-0886

2014-03-2520:55:07
CWE-78
ibm
web.nvd.nist.gov
22
cve-2014-0886
ibm lotus protector
mail security
remote authentication
access restrictions
arbitrary commands
security vulnerability
nvd

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.011

Percentile

84.3%

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.

Affected configurations

Nvd
Node
ibmlotus_protector_for_mail_securityMatch2.8
OR
ibmlotus_protector_for_mail_securityMatch2.8.1
VendorProductVersionCPE
ibmlotus_protector_for_mail_security2.8cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.8:*:*:*:*:*:*:*
ibmlotus_protector_for_mail_security2.8.1cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.8.1:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.011

Percentile

84.3%

Related for CVE-2014-0886