Vulnerability Name: | CVE-2014-8553 (CCN-99257) | ||||||||||||
Assigned: | 2014-12-08 | ||||||||||||
Published: | 2014-12-08 | ||||||||||||
Updated: | 2017-09-08 | ||||||||||||
Summary: | The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive information via a (1) mc_project_get_users, (2) mc_issue_get, (3) mc_filter_get_issues, or (4) mc_project_get_issues SOAP request. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-8553 Source: MLIST Type: UNKNOWN [oss-security] 20141207 MantisBT 1.2.18 Released Source: SECUNIA Type: UNKNOWN 62101 Source: DEBIAN Type: UNKNOWN DSA-3120 Source: CCN Type: BID-71553 MantisBT 'soap/mc_account_api.php' Security Bypass Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1171783 (CVE-2014-8553) CVE-2014-8553 mantis: user real name and email disclosure in SOAP API Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=1171783 Source: XF Type: UNKNOWN mantisbt-cve20148553-info-disc(99257) Source: XF Type: UNKNOWN mantisbt-cve20148553-info-disc(99257) Source: CONFIRM Type: UNKNOWN https://github.com/mantisbt/mantisbt/commit/f779e3d4394a0638d822849863c4098421d911c5 Source: CCN Type: MantisBT Web site MantisBT Source: CONFIRM Type: UNKNOWN https://www.mantisbt.org/bugs/changelog_page.php?version_id=191 Source: CONFIRM Type: Vendor Advisory https://www.mantisbt.org/bugs/view.php?id=17243 Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-8553 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |