Vulnerability Name: | CVE-2013-5445 (CCN-87821) | ||||||||
Assigned: | 2013-08-22 | ||||||||
Published: | 2014-03-20 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key. Per: http://www-01.ibm.com/support/docview.wss?uid=swg21667626 "Encrypted credentials can be remotely retrieved from the IBM Cognos Express server." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5445 Source: CCN Type: IBM Security Bulletin 1667626 Multiple vulnerabilities in IBM Cognos Express (CVE-2013-5443, CVE-2013-5445, CVE-2013-5444, CVE-2013-2407, CVE-2013-2450, CVE-2013-0169, CVE-2013-1478, CVE-2013-1480) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21667626 Source: CCN Type: BID-66361 IBM Cognos Express CVE-2013-5445 Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-cognos-cve20135445-info-disc(87821) Source: XF Type: UNKNOWN ibm-cognos-cve20135445-info-disc(87821) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |