4.3
CVE-2014-0936
- EPSS 0.24%
- Veröffentlicht 08.06.2014 23:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Security Appscan Source Version8.0
Ibm ≫ Security Appscan Source Version8.5
Ibm ≫ Security Appscan Source Version8.6
Ibm ≫ Security Appscan Source Version8.7
Ibm ≫ Security Appscan Source Version8.8
Ibm ≫ Security Appscan Source Version9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.439 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 3.2 | 6.4 |
AV:A/AC:H/Au:N/C:P/I:P/A:P
|