CVE-2014-6148
Summary
| CVE | CVE-2014-6148 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-31 10:55:00 UTC |
| Updated | 2017-09-08 01:29:00 UTC |
| Description | IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sensitive database information via a crafted URL. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM Tivoli Application Dependency Discovery Manager (TADDM) can reveal TADDM database sensitive information (CVE-2014-6148) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| Security Advisory SA61785 - IBM Tivoli Application Dependency Discovery Manager Two Vulnerabilities - Secunia | SECUNIA | secunia.com | |
| Tivoli Application Dependency Discovery Manager CVE-2014-6148 Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.