CVE-2014-3064
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read…
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter.
- CVSS 2.0
- 6.3 MEDIUMAV:N/AC:M/Au:S/C:C/I:N/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/infosphere master data management collaboration server · ibm/infosphere master data management server for product information management
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21677299Vendor Advisory
- http://www.securityfocus.com/bid/69027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93600
- http://www-01.ibm.com/support/docview.wss?uid=swg21677299Vendor Advisory
- http://www.securityfocus.com/bid/69027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93600
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.