CVE-2014-1930
Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote…
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- visibility software/cyber recruiter
- Source
- cve@mitre.org
References
- http://jvn.jp/vu/JVNVU97441356/index.html
- http://osvdb.org/102814
- http://osvdb.org/102815
- http://www.kb.cert.org/vuls/id/566894US Government Resource
- http://www.securityfocus.com/bid/65305
- http://www.vspublic.com/help/Cyber%20Recruiter/default.aspx?pageid=release_detailsVendor Advisory
- http://jvn.jp/vu/JVNVU97441356/index.html
- http://osvdb.org/102814
- http://osvdb.org/102815
- http://www.kb.cert.org/vuls/id/566894US Government Resource
- http://www.securityfocus.com/bid/65305
- http://www.vspublic.com/help/Cyber%20Recruiter/default.aspx?pageid=release_detailsVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.