Lucene search

K
cveIbmCVE-2014-6134
HistoryMar 25, 2015 - 1:59 a.m.

CVE-2014-6134

2015-03-2501:59:03
CWE-200
ibm
web.nvd.nist.gov
29
ibm
rational clearcase
installation manager
security
passwords
memory
vulnerability
cve-2014-6134

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%

IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation account.

Affected configurations

Nvd
Node
ibminstallation_managerRange1.8.1.0
Node
ibmrational_clearcaseMatch8.0.0
OR
ibmrational_clearcaseMatch8.0.0.1
OR
ibmrational_clearcaseMatch8.0.0.2
OR
ibmrational_clearcaseMatch8.0.0.3
OR
ibmrational_clearcaseMatch8.0.0.4
OR
ibmrational_clearcaseMatch8.0.0.5
OR
ibmrational_clearcaseMatch8.0.0.6
OR
ibmrational_clearcaseMatch8.0.0.7
OR
ibmrational_clearcaseMatch8.0.0.8
OR
ibmrational_clearcaseMatch8.0.0.9
OR
ibmrational_clearcaseMatch8.0.0.10
OR
ibmrational_clearcaseMatch8.0.0.11
OR
ibmrational_clearcaseMatch8.0.0.12
OR
ibmrational_clearcaseMatch8.0.0.13
OR
ibmrational_clearcaseMatch8.0.1
OR
ibmrational_clearcaseMatch8.0.1.1
OR
ibmrational_clearcaseMatch8.0.1.2
OR
ibmrational_clearcaseMatch8.0.1.3
OR
ibmrational_clearcaseMatch8.0.1.4
OR
ibmrational_clearcaseMatch8.0.1.5
OR
ibmrational_clearcaseMatch8.0.1.6
VendorProductVersionCPE
ibminstallation_manager*cpe:2.3:a:ibm:installation_manager:*:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0cpe:2.3:a:ibm:rational_clearcase:8.0.0:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.1cpe:2.3:a:ibm:rational_clearcase:8.0.0.1:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.2cpe:2.3:a:ibm:rational_clearcase:8.0.0.2:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.3cpe:2.3:a:ibm:rational_clearcase:8.0.0.3:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.4cpe:2.3:a:ibm:rational_clearcase:8.0.0.4:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.5cpe:2.3:a:ibm:rational_clearcase:8.0.0.5:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.6cpe:2.3:a:ibm:rational_clearcase:8.0.0.6:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.7cpe:2.3:a:ibm:rational_clearcase:8.0.0.7:*:*:*:*:*:*:*
ibmrational_clearcase8.0.0.8cpe:2.3:a:ibm:rational_clearcase:8.0.0.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 221

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2014-6134