CVE Vulnerabilities

CVE-2014-0936

Published: Jun 08, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:A/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

NameVendorStart VersionEnd Version
Security_appscan_sourceIbm8.0 (including)8.0 (including)
Security_appscan_sourceIbm8.5 (including)8.5 (including)
Security_appscan_sourceIbm8.6 (including)8.6 (including)
Security_appscan_sourceIbm8.7 (including)8.7 (including)
Security_appscan_sourceIbm8.8 (including)8.8 (including)
Security_appscan_sourceIbm9.0 (including)9.0 (including)

References