Lucene search

K
cveIbmCVE-2014-6148
HistoryOct 31, 2014 - 10:55 a.m.

CVE-2014-6148

2014-10-3110:55:02
CWE-287
ibm
web.nvd.nist.gov
24
ibm
tivoli
application
dependency
discovery
manager
taddm
cve-2014-6148
nvd
security
vulnerability
authentication
remote
database

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.001

Percentile

49.3%

IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sensitive database information via a crafted URL.

Affected configurations

Nvd
Node
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.0
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.1
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.2
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.3
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.4
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.5
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.6
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.7
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.8
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.9
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.0.10
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.1
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.1.1
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.1.2
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.1.3
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.1.4
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.1.5
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.1.6
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.2
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.2.1
OR
ibmtivoli_application_dependency_discovery_managerMatch7.2.2.2
VendorProductVersionCPE
ibmtivoli_application_dependency_discovery_manager7.2.0.0cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.0:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.1cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.1:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.2cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.2:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.3cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.3:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.4cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.4:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.5cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.5:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.6cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.6:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.7cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.7:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.8cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.8:*:*:*:*:*:*:*
ibmtivoli_application_dependency_discovery_manager7.2.0.9cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.0.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.001

Percentile

49.3%

Related for CVE-2014-6148