Lucene search

K
cveIbmCVE-2014-3089
HistoryAug 22, 2014 - 1:55 a.m.

CVE-2014-3089

2014-08-2201:55:08
CWE-310
ibm
web.nvd.nist.gov
23
ibm
rds
java client
rational directory server
cve-2014-3089
security vulnerability

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0

Percentile

5.1%

The RDS Java Client library in IBM Rational Directory Server (RDS) 5.1.1.x before 5.1.1.2 iFix004 and 5.2.x before 5.2.1 iFix003, and Rational Directory Administrator (RDA) 6.0 before iFix002, includes the cleartext root password, which allows local users to obtain sensitive information by reading a library file.

Affected configurations

Nvd
Node
ibmrational_directory_administratorMatch6.0
OR
ibmrational_directory_administratorMatch6.0.0.1
OR
ibmrational_directory_serverMatch5.1.1
OR
ibmrational_directory_serverMatch5.1.1.1
OR
ibmrational_directory_serverMatch5.1.1.2
OR
ibmrational_directory_serverMatch5.2
OR
ibmrational_directory_serverMatch5.2.0.1
OR
ibmrational_directory_serverMatch5.2.0.2
OR
ibmrational_directory_serverMatch5.2.1
VendorProductVersionCPE
ibmrational_directory_administrator6.0cpe:2.3:a:ibm:rational_directory_administrator:6.0:*:*:*:*:*:*:*
ibmrational_directory_administrator6.0.0.1cpe:2.3:a:ibm:rational_directory_administrator:6.0.0.1:*:*:*:*:*:*:*
ibmrational_directory_server5.1.1cpe:2.3:a:ibm:rational_directory_server:5.1.1:*:*:*:*:*:*:*
ibmrational_directory_server5.1.1.1cpe:2.3:a:ibm:rational_directory_server:5.1.1.1:*:*:*:*:*:*:*
ibmrational_directory_server5.1.1.2cpe:2.3:a:ibm:rational_directory_server:5.1.1.2:*:*:*:*:*:*:*
ibmrational_directory_server5.2cpe:2.3:a:ibm:rational_directory_server:5.2:*:*:*:*:*:*:*
ibmrational_directory_server5.2.0.1cpe:2.3:a:ibm:rational_directory_server:5.2.0.1:*:*:*:*:*:*:*
ibmrational_directory_server5.2.0.2cpe:2.3:a:ibm:rational_directory_server:5.2.0.2:*:*:*:*:*:*:*
ibmrational_directory_server5.2.1cpe:2.3:a:ibm:rational_directory_server:5.2.1:*:*:*:*:*:*:*

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2014-3089