4.3
CVE-2014-8921
- EPSS 1.79%
- Veröffentlicht 02.03.2015 02:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Notes Traveler Companion Version 1.0 SwPlatform windows_phone
Ibm ≫ Notes Traveler Companion Version 1.1 SwPlatform windows_phone
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.79% | 0.755 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www-01.ibm.com/support/docview.wss?uid=swg21690582