Lucene search

K
cveIbmCVE-2014-3060
HistoryOct 02, 2014 - 12:55 a.m.

CVE-2014-3060

2014-10-0200:55:03
ibm
web.nvd.nist.gov
22
cve-2014-3060
ibm
websphere
datapower
xc10
appliance
vulnerability
remote attackers
administrative privileges
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.005

Percentile

77.1%

Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie.

Affected configurations

Nvd
Node
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.5.0.0
AND
ibmwebsphere_datapower_xc10_applianceMatch-
VendorProductVersionCPE
ibmwebsphere_datapower_xc10_appliance_firmware2.5.0.0cpe:2.3:o:ibm:websphere_datapower_xc10_appliance_firmware:2.5.0.0:*:*:*:*:*:*:*
ibmwebsphere_datapower_xc10_appliance-cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.005

Percentile

77.1%

Related for CVE-2014-3060