First published: Fri Aug 29 2014(Updated: )
The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security AppScan | >=8.0.0.0<8.6.0.2 | |
IBM Security AppScan | >=8.7.0.0<8.7.0.1 | |
IBM Security AppScan | >=8.8.0.0<8.8.0.1 | |
IBM Security AppScan | >=9.0.0.0<9.0.0.1 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4806 is considered a high severity vulnerability due to the exposure of sensitive information through a cleartext password.
CVE-2014-4806 allows local users on Linux systems to access cleartext passwords stored in temporary files during the installation process.
To fix CVE-2014-4806, update IBM Security AppScan to a version that includes iFix 003 or later for the affected versions.
CVE-2014-4806 affects IBM Security AppScan Enterprise versions 8.x before 8.6.0.2, 8.7.x before 8.7.0.1, 8.8.x before 8.8.0.1, and 9.0.x before 9.0.0.1.
CVE-2014-4806 is a local vulnerability, as it requires local user access to exploit the exposure of sensitive information.