Lucene search

K
kasperskyKaspersky LabKLA10208
HistorySep 08, 2013 - 12:00 a.m.

KLA10208 OSI vulnerability in IBM Security AppScan

2013-09-0800:00:00
Kaspersky Lab
threats.kaspersky.com
49

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

52.3%

Weak encryption algorithms were found in IBM Security AppScan. By exploiting this vulnerability malicious users can obtain sensitive information. This vulnerability can be exploited remotely at a point related to SSL.

Original advisories

Related products

IBM-Security-AppScan-(formerly-IBM-Rational-AppScan)

CVE list

CVE-2013-0531 critical

Solution

Update to latest version

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

Affected Products

  • IBM Security AppScan Enterprise versions 8.7.0.0 and earlier

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

52.3%