CVE-2014-3089
Summary
| CVE | CVE-2014-3089 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-22 01:55:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The RDS Java Client library in IBM Rational Directory Server (RDS) 5.1.1.x before 5.1.1.2 iFix004 and 5.2.x before 5.2.1 iFix003, and Rational Directory Administrator (RDA) 6.0 before iFix002, includes the cleartext root password, which allows local users to obtain sensitive information by reading a library file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Rational Directory Administrator | 6.0 | All | All | All |
| Application | Ibm | Rational Directory Administrator | 6.0.0.1 | All | All | All |
| Application | Ibm | Rational Directory Server | 5.1.1 | All | All | All |
| Application | Ibm | Rational Directory Server | 5.1.1.1 | All | All | All |
| Application | Ibm | Rational Directory Server | 5.1.1.2 | All | All | All |
| Application | Ibm | Rational Directory Server | 5.2 | All | All | All |
| Application | Ibm | Rational Directory Server | 5.2.0.1 | All | All | All |
| Application | Ibm | Rational Directory Server | 5.2.0.2 | All | All | All |
| Application | Ibm | Rational Directory Server | 5.2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Rational Directory Server CVE-2014-3089 Local Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Bulletin: Critical Security Vulnerability in Rational Directory Server (Tivoli and Apache) (CVE-2014-3089) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.