First published: Wed Sep 10 2014(Updated: )
IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Initiate Master Data Service | =9.5 | |
IBM Initiate Master Data Service | =9.7 | |
IBM Initiate Master Data Service | =10.0 | |
IBM Initiate Master Data Service | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4788 has a medium severity level as it involves improper handling of authentication fields.
To fix CVE-2014-4788, upgrade IBM Initiate Master Data Service to the latest versions, specifically 9.5.093013, 9.7.093013, 10.0.093013, or 10.1.093013.
CVE-2014-4788 affects IBM Initiate Master Data Service versions 9.5, 9.7, 10.0, and 10.1 prior to their respective patch versions.
CVE-2014-4788 enables remote attackers to gain unauthorized access through unattended workstations due to missing autocomplete attributes.
There is no official workaround for CVE-2014-4788; upgrading to the patched versions is the recommended solution.