CVE-2014-6148: Low severity ibm tivoli application dependency discovery manager vulnerability
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sensitive database information via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6148?
CVE-2014-6148 is classified as a medium severity vulnerability.
How does CVE-2014-6148 affect IBM Tivoli Application Dependency Discovery Manager?
CVE-2014-6148 allows remote authenticated users to obtain sensitive database information by crafting specific URLs due to the lack of required authentication for rptdesign downloads.
How do I fix CVE-2014-6148?
To fix CVE-2014-6148, you should apply the latest patches released by IBM for the affected versions of Tivoli Application Dependency Discovery Manager.
Which versions are affected by CVE-2014-6148?
CVE-2014-6148 affects IBM Tivoli Application Dependency Discovery Manager versions from 7.2.0.0 to 7.2.2.2.
Is CVE-2014-6148 a known issue in the IBM security landscape?
Yes, CVE-2014-6148 is a documented vulnerability within IBM's security advisories and has been previously highlighted.