← Back

CVE-2014-4806

nvd nist
Published: Aug 29, 2014Modified: May 6, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file.

Affected (4)

1 product
Security Appscan
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ibm
From 8.0.0.0 to 8.6.0.2
From 8.7.0.0 to 8.7.0.1
From 8.8.0.0 to 8.8.0.1
From 9.0.0.0 to 9.0.0.1
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (6)

Source: psirt@us.ibm.com
Third Party AdvisoryVDB Entry
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory

Timeline

No history available yet.