Vulnerability Name: | CVE-2013-5430 (CCN-87562) | ||||||||
Assigned: | 2013-10-22 | ||||||||
Published: | 2013-10-22 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, which makes it easier for remote authenticated users to obtain unspecified access to this component by leveraging this credential information in an environment with applicable component installation details. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5430 Source: CCN Type: IBM Security Bulletin 1653287 Multiple vulnerabilities in IBM Security AppScan Enterprise (CVE-2013-4062, CVE-2013-4061, CVE-2013-5430, CVE-2013-3989) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21653287 Source: CCN Type: OSVDB ID: 98888 IBM Security AppScan Enterprise Jazz Team Server Component Default Credentials Source: CCN Type: BID-63294 IBM Security AppScan Enterprise Default Account Authentication Bypass Vulnerability Source: XF Type: UNKNOWN appscan-cve20135430-unauth-access(87562) Source: XF Type: UNKNOWN appscan-cve20135430-default-cred(87562) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |