7.5

CVE-2014-6309

The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TenefitKaazing Websocket Gateway Version4.0.2 SwEditionjms
TenefitKaazing Websocket Gateway Version4.0.3 SwEditionjms
TenefitKaazing Websocket Gateway Version4.0.4 SwEditionjms
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.55% 0.717
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.kaazing.com/hc/en-us/articles/115004550547-Advisory-for-KGS-879
Vendor Advisory
Broken Link
https://support.tenefit.com/hc/en-us/articles/115004550547-Advisory-for-KGS-879
Vendor Advisory