SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1930

Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote…

MEDIUM 4.3EPSS 1.53%

Does this matter?

Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.

Description

Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.53% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
visibility software/cyber recruiter
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.