Lucene search

K
cve[email protected]CVE-2014-4810
HistoryNov 05, 2014 - 11:55 a.m.

CVE-2014-4810

2014-11-0511:55:06
CWE-264
web.nvd.nist.gov
18
ibm
cognos mobile
vulnerability
session preservation
remote attack
authentication data

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.2%

IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for remote attackers to bypass intended Business Intelligence restrictions by leveraging access to authentication data that was captured before this logoff.

Affected configurations

NVD
Node
ibmcognos_mobileMatch10.1.1
OR
ibmcognos_mobileMatch10.2.0
OR
ibmcognos_mobileMatch10.2.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.2%

Related for CVE-2014-4810