First published: Wed May 20 2015(Updated: )
IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM License Metric Tool | =9.0 | |
IBM License Metric Tool | =9.0.1 | |
IBM License Metric Tool | =9.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4776 is considered a medium severity vulnerability due to its potential for unauthorized access via unattended workstations.
To fix CVE-2014-4776, upgrade IBM License Metric Tool to version 9.1.0.2 or later.
IBM License Metric Tool versions 9.0, 9.0.1, and 9.1.0.1 are affected by CVE-2014-4776.
Failing to address CVE-2014-4776 may allow remote attackers to gain unauthorized access to sensitive information.
Yes, CVE-2014-4776 is related to web security as it concerns the inadequate handling of authentication fields in web applications.