Show plain JSON{"id": "CVE-2014-4806", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 2.1, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.5, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 1.8}]}, "published": "2014-08-29T09:55:08.353", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21682642", "tags": ["Broken Link"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securityfocus.com/bid/69435", "tags": ["Third Party Advisory", "VDB Entry"], "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/95354", "tags": ["VDB Entry", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21682642", "tags": ["Broken Link"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/69435", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/95354", "tags": ["VDB Entry", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-522"}]}], "descriptions": [{"lang": "en", "value": "The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file."}, {"lang": "es", "value": "El proceso de instalaci\u00f3n en IBM Security AppScan Enterprise 8.x anterior a 8.6.0.2 iFix 003, 8.7.x anterior a 8.7.0.1 iFix 003, 8.8.x anterior a 8.8.0.1 iFix 002, y 9.0.x anterior a 9.0.0.1 iFix 001 en Linux coloca una contrase\u00f1a en texto plano en un fichero temporal, lo que permite a usuarios locales obtener informaci\u00f3n sensible mediante la lectura de este fichero."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:security_appscan:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "B9B3DB34-0269-4BD1-8740-3593C856086F", "versionEndExcluding": "8.6.0.2", "versionStartIncluding": "8.0.0.0"}, {"criteria": "cpe:2.3:a:ibm:security_appscan:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "F9BA334F-1C90-4877-B43E-2E5CDE748660", "versionEndExcluding": "8.7.0.1", "versionStartIncluding": "8.7.0.0"}, {"criteria": "cpe:2.3:a:ibm:security_appscan:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "8DB5A0AC-923D-4388-BDEA-DAA5C610AC66", "versionEndExcluding": "8.8.0.1", "versionStartIncluding": "8.8.0.0"}, {"criteria": "cpe:2.3:a:ibm:security_appscan:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "02197BFD-4145-425E-B697-08B69817DCB7", "versionEndExcluding": "9.0.0.1", "versionStartIncluding": "9.0.0.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "155AD4FB-E527-4103-BCEF-801B653DEA37"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "psirt@us.ibm.com"}