Vulnerability Name: | CVE-2008-6886 (CCN-46884) | ||||||||
Assigned: | 2008-11-25 | ||||||||
Published: | 2008-11-25 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attackers to obtain the administrator password hash and conduct brute force guessing attacks. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:UR)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:UR)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Nov 25 2008 - 15:54:03 CST RSA EnVision Remote Password Disclosure Source: MITRE Type: CNA CVE-2008-6886 Source: BUGTRAQ Type: Patch 20081125 RSA EnVision Remote Password Disclosure Source: CCN Type: SA32883 RSA EnVision Password Hash Disclosure Vulnerability Source: SECUNIA Type: Vendor Advisory 32883 Source: CCN Type: Apple Web site About the security content of Security Update 2009-001 Source: OSVDB Type: UNKNOWN 50273 Source: CCN Type: OSVDB ID: 50273 RSA enVision Unspecified Remote Password Hash Disclosure Source: CCN Type: RSA Web site RSA enVision Platform Source: MISC Type: Patch http://www.secfault.org/?p=78 Source: BID Type: UNKNOWN 32473 Source: CCN Type: BID-32473 RSA enVision Platform Web Console Password Hash Remote Information Disclosure Vulnerability Source: VUPEN Type: Patch, Vendor Advisory ADV-2008-3288 Source: XF Type: UNKNOWN envision-webconsole-info-disclosure(46884) Source: XF Type: UNKNOWN envision-webconsole-info-disclosure(46884) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |