115 lines
3.7 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2014-0936",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2014-06-08T23:55:02.367",
"lastModified": "2017-08-29T01:34:21.343",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network."
},
{
"lang": "es",
"value": "IBM Security AppScan Source 8.0 hasta 9.0, cuando permiso 'publicar asesoramiento' no est\u00e1 restringido debidamente para el servidor de base de datos configurado, transmite datos de asesoramiento en texto claro, lo que permite a atacantes remotos obtener informaci\u00f3n sensible mediante la captura de trafico de red."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:A/AC:H/Au:N/C:P/I:P/A:P",
"accessVector": "ADJACENT_NETWORK",
"accessComplexity": "HIGH",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.2,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
},
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C3EC310D-7C7F-4B5A-AFFC-58A38B67A0CA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.5:*:*:*:*:*:*:*",
"matchCriteriaId": "6990B7A5-3C72-494B-A512-23E508B71CE4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.6:*:*:*:*:*:*:*",
"matchCriteriaId": "0C721146-29F1-4785-B6D6-D43389B6CD2D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.7:*:*:*:*:*:*:*",
"matchCriteriaId": "B205BA6C-A211-4D1D-B342-598B3057B642"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.8:*:*:*:*:*:*:*",
"matchCriteriaId": "7E024F44-EC78-472F-B186-DF5E882D1217"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_appscan_source:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0F890EA4-7122-4AD1-B0C2-1F6D8B67D021"
}
]
}
]
}
],
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21674750",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/92317",
"source": "psirt@us.ibm.com"
}
]
}