Vulnerability Name: | CVE-2014-6120 (CCN-96721) | ||||||||||||
Assigned: | 2014-12-16 | ||||||||||||
Published: | 2014-12-16 | ||||||||||||
Updated: | 2018-05-11 | ||||||||||||
Summary: | IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-77 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-6120 Source: CCN Type: IBM Security Bulletin 1692999 Multiple vulnerabilities in AppScan Source (CVE-2014-4812, CVE-2014-6123) Source: XF Type: UNKNOWN ibm-appscan-cve20146120-command-exec(96721) Source: XF Type: VDB Entry, Vendor Advisory ibm-appscan-cve20146120-command-exec(96721) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||
BACK |