9.1

CVE-2014-1409

Exploit
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MobileironSentry Version < 5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.05% 0.893
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-91 XML Injection (aka Blind XPath Injection)

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

http://seclists.org/fulldisclosure/2014/Apr/21
Third Party Advisory
Exploit
Mailing List
https://exchange.xforce.ibmcloud.com/vulnerabilities/92351
Third Party Advisory
VDB Entry
https://packetstormsecurity.com/files/cve/CVE-2014-1409
Third Party Advisory
VDB Entry