CVE-2014-4822
Summary
| CVE | CVE-2014-4822 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-19 01:55:14 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Mq | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Mq Explorer | 7.5.0.0 | All | All | All |
| Application | Ibm | Websphere Mq Explorer | 7.5.0.1 | All | All | All |
| Application | Ibm | Websphere Mq Explorer | 7.5.0.2 | All | All | All |
| Application | Ibm | Websphere Mq Explorer | 7.5.0.3 | All | All | All |
| Application | Ibm | Websphere Mq Explorer | 7.5.0.4 | All | All | All |
| Application | Ibm | Websphere Mq Explorer | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Mq Explorer | 8.0.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM Security Bulletin: IBM WebSphere MQ is affected by a vulnerability in the WebSphere MQ classes for Java libraries and WebSphere MQ Explorer (CVE-2014-4822) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.