Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-4788

Опубликовано: 10 сент. 2014
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:initiate_master_data_service:9.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:initiate_master_data_service:9.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:initiate_master_data_service:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:initiate_master_data_service:10.1:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00286
Низкий

5 Medium

CVSS2

Дефекты

CWE-255

Связанные уязвимости

github
больше 3 лет назад

IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

EPSS

Процентиль: 52%
0.00286
Низкий

5 Medium

CVSS2

Дефекты

CWE-255