CVE-2014-0857
Published May 1, 2014
Last updated 7 years ago
Overview
- Description
- The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FD8F9CE-4E98-4187-B84A-429FA1C65E2D" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC1D7570-4AB4-44B0-B5ED-D103F0946F63" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E709E36-B5D0-42E5-A305-AF385FD7F347" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49506702-1B31-4421-8DEE-5B789272EC6E" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "158777FD-83D1-44B9-83B4-A3F490CA76F4" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0905C80-A1BA-49CD-90CA-9270ECC3940C" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF1667C5-D19B-469C-82D5-8406B6D75EDE" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89551609-69B7-452A-9CB2-04C12D268B41" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF27B7D7-4442-47CA-880D-D3B5412AEF9D" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B595B048-4204-49B4-9497-B8D119C8784D" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC38B5D4-66A3-4671-9099-0F38D283BA94" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B357DB53-061F-43D5-9E9F-5D5468A5805B" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29ADADD2-EC21-4C45-A381-BC2091CD9F7B" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AD901DE-9258-40DA-A09B-B0CA9DCCF843" }, { "criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C21DDD3-C1CF-4CB2-BA13-4807F17AC5E1" } ], "operator": "OR" } ] } ]