CVE Vulnerabilities

CVE-2014-0936

Published: Jun 08, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:A/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Security_appscan_source Ibm 8.0 (including) 8.0 (including)
Security_appscan_source Ibm 8.5 (including) 8.5 (including)
Security_appscan_source Ibm 8.6 (including) 8.6 (including)
Security_appscan_source Ibm 8.7 (including) 8.7 (including)
Security_appscan_source Ibm 8.8 (including) 8.8 (including)
Security_appscan_source Ibm 9.0 (including) 9.0 (including)

References