| Vulnerability Name: | CVE-2014-4822 (CCN-95467) | ||||||||
| Assigned: | 2014-10-13 | ||||||||
| Published: | 2014-10-13 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N) 1.4 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-255 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2014-4822 Source: SECUNIA Type: UNKNOWN 59921 Source: AIXAPAR Type: UNKNOWN IT04023 Source: CCN Type: IBM Security Bulletin 1686339 IBM WebSphere MQ is affected by a vulnerability in the WebSphere MQ classes for Java libraries and WebSphere MQ Explorer (CVE-2014-4822) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21686339 Source: CCN Type: BID-70588 IBM WebSphere MQ CVE-2014-4822 Local Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-websphere-cve20144822-info-disc(95467) Source: XF Type: UNKNOWN ibm-webspheremq-cve20144822-java(95467) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||