{"api_version":"1","generated_at":"2026-07-23T06:44:22+00:00","cve":"CVE-2018-17484","urls":{"html":"https://cve.report/CVE-2018-17484","api":"https://cve.report/api/cve/CVE-2018-17484.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-17484","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-17484"},"summary":{"title":"CVE-2018-17484","description":"Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-03-21 16:00:00","updated_at":"2019-10-09 23:36:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/149644","name":"lobby-track-cve201817484-info-disc (149644)","refsource":"XF","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-17484","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17484","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"17484","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jollytech","cpe5":"lobby_track","cpe6":"8.2.186","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"desktop","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"17484","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jollytech","cpe5":"lobby_track","cpe6":"8.2.186","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"desktop","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"references":{"reference_data":[{"title":"X-Force Vulnerability Report","name":"lobby-track-cve201817484-info-disc (149644)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/149644"}]},"description":{"description_data":[{"value":"Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database.","lang":"eng"}]},"data_version":"4.0","problemtype":{"problemtype_data":[{"description":[{"value":"Obtain Information","lang":"eng"}]}]},"data_type":"CVE","affects":{"vendor":{"vendor_data":[{"vendor_name":"Jolly Technologies","product":{"product_data":[{"product_name":"Lobby Track Desktop","version":{"version_data":[{"version_value":"8.2.186"}]}}]}}]}},"impact":{"cvssv3":{"TM":{"RC":"R","E":"U","RL":"U"},"BM":{"I":"L","AV":"L","A":"N","PR":"N","UI":"N","S":"U","AC":"H","C":"L","SCORE":"4.000"}}},"data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2018-17484","STATE":"PUBLIC","ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2019-03-04T00:00:00"}},"nvd":{"publishedDate":"2019-03-21 16:00:00","lastModifiedDate":"2019-10-09 23:36:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.6},"severity":"LOW","exploitabilityScore":3.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jollytech:lobby_track:8.2.186:*:*:*:desktop:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"17484","Ordinal":"134297","Title":"CVE-2018-17484","CVE":"CVE-2018-17484","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"17484","Ordinal":"1","NoteData":"Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"17484","Ordinal":"2","NoteData":"2019-03-19","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"17484","Ordinal":"3","NoteData":"2019-03-19","Type":"Other","Title":"Modified"}]}}}