Vulnerability CVE-2014-6122


Published: 2014-12-22   Modified: 2014-12-23

Description:
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to write to arbitrary folders, and consequently execute arbitrary commands, via a modified argument.

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.5/10
4.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
Partial
Affected software
IBM -> Security appscan 
IBM -> Security appscan source 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg21693035
http://www.securitytracker.com/id/1031427
https://exchange.xforce.ibmcloud.com/vulnerabilities/96723

Copyright 2024, cxsecurity.com

 

Back to Top