Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0863


The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified security tool.


Published

2014-09-05T01:55:10.893

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm cognos_tm1 9.5.2.3 Yes
Application ibm cognos_tm1 10.1.1.2 Yes
Application ibm cognos_tm1 10.2.0.2 Yes
Application ibm cognos_tm1 10.2.2 Yes

References