CVE-2014-8895
IBM TRIRIGA Application Platform <3.3.2.3-<3.4.1.1 - Auth Bypass
Title source: llmDescription
IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72430
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21694771
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62674
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99014
Scores
EPSS
0.0124
EPSS Percentile
66.1%
Details
CWE
CWE-264
Status
published
Products (7)
ibm/tririga_application_platform
3.2.1
ibm/tririga_application_platform
3.3.2.0
ibm/tririga_application_platform
3.3.2.1
ibm/tririga_application_platform
3.3.2.2
ibm/tririga_application_platform
3.4.0.0
ibm/tririga_application_platform
3.4.0.1
ibm/tririga_application_platform
3.4.1.0
Published
Jan 29, 2015
Tracked Since
Feb 18, 2026