PT-2014-7067 · Ibm · Taddm

Publicado

2014-10-31

·

Atualizado

2017-09-08

·

CVE-2014-6148

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Application Dependency Discovery Manager (TADDM) versions 7.2.0.0 through 7.2.0.10 IBM Tivoli Application Dependency Discovery Manager (TADDM) versions 7.2.1.0 through 7.2.1.6 IBM Tivoli Application Dependency Discovery Manager (TADDM) versions 7.2.2.0 through 7.2.2.2
Description The issue allows remote authenticated users to obtain sensitive database information via a crafted URL, as TADDM does not require authentication for rptdesign downloads.
Recommendations For versions 7.2.0.0 through 7.2.0.10, consider implementing authentication for rptdesign downloads to prevent unauthorized access. For versions 7.2.1.0 through 7.2.1.6, consider implementing authentication for rptdesign downloads to prevent unauthorized access. For versions 7.2.2.0 through 7.2.2.2, consider implementing authentication for rptdesign downloads to prevent unauthorized access.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-6148

Produtos afetados

Taddm