CVE-2014-2536

medium

Description

Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown vectors.

References

https://kc.mcafee.com/corporate/index?page=content&id=SB10066

http://www.securityfocus.com/bid/66181

http://secunia.com/advisories/57381

http://secunia.com/advisories/57368

Details

Source: Mitre, NVD

Published: 2014-03-18

Updated: 2014-04-01

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium