Lucene search

K
cve[email protected]CVE-2014-8890
HistoryDec 18, 2014 - 4:59 p.m.

CVE-2014-8890

2014-12-1816:59:17
CWE-264
web.nvd.nist.gov
34
cve-2014-8890
ibm
websphere
application server
liberty profile
remote attackers
privileges
servlet
security constraints
servletsecurity annotations

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

5.3 Medium

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.3%

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet’s deployment descriptor security constraints and ServletSecurity annotations.

Affected configurations

NVD
Node
ibmwebsphere_application_serverMatch8.5.0.0
OR
ibmwebsphere_application_serverMatch8.5.0.1
OR
ibmwebsphere_application_serverMatch8.5.0.2
OR
ibmwebsphere_application_serverMatch8.5.5.0
OR
ibmwebsphere_application_serverMatch8.5.5.1
OR
ibmwebsphere_application_serverMatch8.5.5.2
OR
ibmwebsphere_application_serverMatch8.5.5.3

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

5.3 Medium

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.3%

Related for CVE-2014-8890