Lucene search

K
nvd[email protected]NVD:CVE-2014-0936
HistoryJun 08, 2014 - 11:55 p.m.

CVE-2014-0936

2014-06-0823:55:02
CWE-310
CWE-264
web.nvd.nist.gov
2

CVSS2

4.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:H/Au:N/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0.003

Percentile

65.7%

IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected configurations

Nvd
Node
ibmsecurity_appscan_sourceMatch8.0
OR
ibmsecurity_appscan_sourceMatch8.5
OR
ibmsecurity_appscan_sourceMatch8.6
OR
ibmsecurity_appscan_sourceMatch8.7
OR
ibmsecurity_appscan_sourceMatch8.8
OR
ibmsecurity_appscan_sourceMatch9.0
VendorProductVersionCPE
ibmsecurity_appscan_source8.0cpe:2.3:a:ibm:security_appscan_source:8.0:*:*:*:*:*:*:*
ibmsecurity_appscan_source8.5cpe:2.3:a:ibm:security_appscan_source:8.5:*:*:*:*:*:*:*
ibmsecurity_appscan_source8.6cpe:2.3:a:ibm:security_appscan_source:8.6:*:*:*:*:*:*:*
ibmsecurity_appscan_source8.7cpe:2.3:a:ibm:security_appscan_source:8.7:*:*:*:*:*:*:*
ibmsecurity_appscan_source8.8cpe:2.3:a:ibm:security_appscan_source:8.8:*:*:*:*:*:*:*
ibmsecurity_appscan_source9.0cpe:2.3:a:ibm:security_appscan_source:9.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:H/Au:N/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0.003

Percentile

65.7%

Related for NVD:CVE-2014-0936