CVE-2014-0936

CWE-264CWE-3103 documents3 sources
Severity
4.3MEDIUM
EPSS
0.2%
top 53.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMay 17

Description

IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS vector

AV:A/AC:H/C:P/I:P/A:PExploitability: 3.2 | Impact: 6.4

Affected Packages1 packages

NVDibm/security_appscan_source6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-m626-ggjg-w8g8: IBM Security AppScan Source 82022-05-17
CVEList
CVE-2014-0936: IBM Security AppScan Source 82014-06-08
CVE-2014-0936 (MEDIUM CVSS 4.3) | IBM Security AppScan Source 8.0 thr | cvebase.io