Vulnerability Name: | CVE-2014-6134 (CCN-96814) | ||||||||
Assigned: | 2014-09-02 | ||||||||
Published: | 2015-03-18 | ||||||||
Updated: | 2015-03-25 | ||||||||
Summary: | IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation account. | ||||||||
CVSS v3 Severity: | 2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N) 0.9 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
0.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-6134 Source: CCN Type: IBM Security Bulletin 1688450 ClearCase installer exposes server passwords in memory (CVE-2014-6134) Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21688450 Source: XF Type: UNKNOWN ibm-clearcase-cve20146134-info-disc(96814) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
BACK |