CVE-2014-0842
Last modified
CVE-2014-0842 is a vulnerability of currently unknown severity. The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Rational Focal Point | 6.4 |
| Ibm | Rational Focal Point | 6.4.0.1 |
| Ibm | Rational Focal Point | 6.4.1.0 |
| Ibm | Rational Focal Point | 6.4.1.1 |
| Ibm | Rational Focal Point | 6.4.1.2 |
| Ibm | Rational Focal Point | 6.4.1.3 |
| Ibm | Rational Focal Point | 6.5 |
| Ibm | Rational Focal Point | 6.5.0.1 |
| Ibm | Rational Focal Point | 6.5.0.2 |
| Ibm | Rational Focal Point | 6.5.1 |
| Ibm | Rational Focal Point | 6.5.1.1 |
| Ibm | Rational Focal Point | 6.5.2 |
| Ibm | Rational Focal Point | 6.5.2.1 |
| Ibm | Rational Focal Point | 6.5.2.2 |
| Ibm | Rational Focal Point | 6.5.2.3 |
| Ibm | Rational Focal Point | 6.6 |
| Ibm | Rational Focal Point | 6.6.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0842?
How severe is CVE-2014-0842?
How do I fix CVE-2014-0842?
Are you affected by CVE-2014-0842?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
