5
CVE-2014-0842
- EPSS 1.17%
- Veröffentlicht 26.02.2014 01:29:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Rational Focal Point Version 6.4
Ibm ≫ Rational Focal Point Version 6.4.0.1
Ibm ≫ Rational Focal Point Version 6.4.1.0
Ibm ≫ Rational Focal Point Version 6.4.1.1
Ibm ≫ Rational Focal Point Version 6.4.1.2
Ibm ≫ Rational Focal Point Version 6.4.1.3
Ibm ≫ Rational Focal Point Version 6.5
Ibm ≫ Rational Focal Point Version 6.5.0.1
Ibm ≫ Rational Focal Point Version 6.5.0.2
Ibm ≫ Rational Focal Point Version 6.5.1
Ibm ≫ Rational Focal Point Version 6.5.1.1
Ibm ≫ Rational Focal Point Version 6.5.2
Ibm ≫ Rational Focal Point Version 6.5.2.1
Ibm ≫ Rational Focal Point Version 6.5.2.2
Ibm ≫ Rational Focal Point Version 6.5.2.3
Ibm ≫ Rational Focal Point Version 6.6
Ibm ≫ Rational Focal Point Version 6.6.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.634 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://www-01.ibm.com/support/docview.wss?uid=swg21665005
https://exchange.xforce.ibmcloud.com/vulnerabilities/90706