CVE-2014-0936

IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
ADJACENT_NETWORK
HIGH
AV:A/AC:H/Au:N/C:P/I:P/A:P
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
VendorProductVersion
ibmsecurity_appscan_source
8.0
ibmsecurity_appscan_source
8.5
ibmsecurity_appscan_source
8.6
ibmsecurity_appscan_source
8.7
ibmsecurity_appscan_source
8.8
ibmsecurity_appscan_source
9.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration