{"api_version":"1","generated_at":"2026-07-23T13:34:56+00:00","cve":"CVE-2015-8989","urls":{"html":"https://cve.report/CVE-2015-8989","api":"https://cve.report/api/cve/CVE-2015-8989.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-8989","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-8989"},"summary":{"title":"CVE-2015-8989","description":"Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.","state":"PUBLISHED","assigner":"intel","published_at":"2017-03-14 22:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-310","Unsalted password vulnerability"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10117","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10117","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"McAfee KnowledgeBase - Intel Security - Security Bulletin: Vulnerability Manager 7.5.9 update provides password salting for all user passwords","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-8989","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-8989","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Intel","product":"McAfee Vulnerability Manager (MVM)","version":"affected 7.5.8 and earlier","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"8989","vulnerable":"1","versionEndIncluding":"7.5.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"vulnerability_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T08:36:31.043Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10117"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"McAfee Vulnerability Manager (MVM)","vendor":"Intel","versions":[{"status":"affected","version":"7.5.8 and earlier"}]}],"datePublic":"2015-05-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database."}],"problemTypes":[{"descriptions":[{"description":"Unsalted password vulnerability","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-03-14T21:57:01.000Z","orgId":"6dda929c-bb53-4a77-a76d-48e79601a1ce","shortName":"intel"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10117"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@intel.com","ID":"CVE-2015-8989","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"McAfee Vulnerability Manager (MVM)","version":{"version_data":[{"version_value":"7.5.8 and earlier"}]}}]},"vendor_name":"Intel"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Unsalted password vulnerability"}]}]},"references":{"reference_data":[{"name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10117","refsource":"CONFIRM","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10117"}]}}}},"cveMetadata":{"assignerOrgId":"6dda929c-bb53-4a77-a76d-48e79601a1ce","assignerShortName":"intel","cveId":"CVE-2015-8989","datePublished":"2017-03-14T22:00:00.000Z","dateReserved":"2017-02-27T00:00:00.000Z","dateUpdated":"2024-08-06T08:36:31.043Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-14 22:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-310","Unsalted password vulnerability"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:vulnerability_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"7.5.8","matchCriteriaId":"62A41E3B-F8BD-4D0F-8CA2-35FCA727C92C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"8989","Ordinal":"1","Title":"CVE-2015-8989","CVE":"CVE-2015-8989","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"8989","Ordinal":"1","NoteData":"Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.","Type":"Description","Title":"CVE-2015-8989"},{"CveYear":"2015","CveId":"8989","Ordinal":"2","NoteData":"2017-03-14","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"8989","Ordinal":"3","NoteData":"2017-03-14","Type":"Other","Title":"Modified"}]}}}