CVE-2014-0936

IBM Security AppScan Source 8.0-9.0 - Cleartext Transmission of Sensitive Assessment Data

Title source: llm
STIX 2.1

Description

IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21674750
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/92317

Scores

EPSS 0.0063
EPSS Percentile 46.4%

Details

CWE
CWE-264 CWE-310
Status published
Products (6)
ibm/security_appscan_source 8.0
ibm/security_appscan_source 8.5
ibm/security_appscan_source 8.6
ibm/security_appscan_source 8.7
ibm/security_appscan_source 8.8
ibm/security_appscan_source 9.0
Published Jun 08, 2014
Tracked Since Feb 18, 2026