Show plain JSON{"id": "CVE-2014-0866", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2014-07-07T11:01:28.823", "references": [{"url": "http://packetstormsecurity.com/files/127304/IBM-Algorithmics-RICOS-Disclosure-XSS-CSRF.html", "source": "psirt@us.ibm.com"}, {"url": "http://seclists.org/fulldisclosure/2014/Jun/173", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21675881", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securityfocus.com/archive/1/532598/100/0/threaded", "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90940", "source": "psirt@us.ibm.com"}, {"url": "https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140630-0_IBM_Algorithmics_RICOS_multiple_vulnerabilities_v10.txt", "source": "psirt@us.ibm.com"}, {"url": "http://packetstormsecurity.com/files/127304/IBM-Algorithmics-RICOS-Disclosure-XSS-CSRF.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://seclists.org/fulldisclosure/2014/Jun/173", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21675881", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/532598/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90940", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140630-0_IBM_Algorithmics_RICOS_multiple_vulnerabilities_v10.txt", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-310"}]}], "descriptions": [{"lang": "en", "value": "RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network."}, {"lang": "es", "value": "RICOS en IBM Algo Credit Limits (tambi\u00e9n conocido como ACLM) 4.5.0 hasta 4.7.0 anterior a 4.7.0.03 FP5 en IBM Algorithmics env\u00eda las credenciales en texto claro sobre HTTP, lo que permite a atacantes remotos obtener informaci\u00f3n sensible mediante la captura de trafico de la red."}], "lastModified": "2024-11-21T02:02:56.367", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:algo_credit_limits:4.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "903D1B5E-A7CF-4D2C-ACF6-56A0A7CAF383"}, {"criteria": "cpe:2.3:a:ibm:algo_credit_limits:4.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF49CDB6-BCF2-4E17-A079-2B8C27BBD39A"}, {"criteria": "cpe:2.3:a:ibm:algorithmics:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9BFFBEC-64CD-44E0-A8FF-A06A2A6BF039"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}