« Volver al listado

CVE-2014-5286

Estado: ModificadaMedia (6.4)—

The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1.2, ActiveMatrix Management Agent 1.x before 1.2.1 for WCF, and ActiveMatrix Management Agent 1.x before 1.2.1 for WebSphere allows remote attackers to gain privileges and obtain sensitive information via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-5286",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-02-19T02:59:28.633",
  "references": [
    {
      "url": "http://www.tibco.com/assets/blt1b18947cad32d1c4/2014-007-advisory.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.tibco.com/mk/advisory.jsp",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.tibco.com/services/support/advisories/activematrix-advisory_20150218",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.tibco.com/assets/blt1b18947cad32d1c4/2014-007-advisory.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.tibco.com/mk/advisory.jsp",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.tibco.com/services/support/advisories/activematrix-advisory_20150218",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1.2, ActiveMatrix Management Agent 1.x before 1.2.1 for WCF, and ActiveMatrix Management Agent 1.x before 1.2.1 for WebSphere allows remote attackers to gain privileges and obtain sensitive information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo ActiveMatrix Policy Manager Authentication en TIBCO ActiveMatrix Policy Agent 3.x anterior a 3.1.2, ActiveMatrix Policy Manager 3.x anterior a 3.1.2, ActiveMatrix Management Agent 1.x anterior a 1.2.1 para WCF, y ActiveMatrix Management Agent 1.x anterior a 1.2.1 para WebSphere permite a atacantes remotos ganar privilegios y obtener información sensible a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:11:20.193",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_management_agent:1.0.0:*:*:*:*:websphere:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB3063F2-3B1A-45CD-A8D6-95DA8DE7CB8E"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_management_agent:1.0.0:*:*:*:*:windows_communication_foundation:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6966EA26-3DFB-4D2B-B784-12B27D580658"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_management_agent:1.1.0:*:*:*:*:websphere:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DD30572-B190-43EA-8018-F1CC83485143"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_management_agent:1.1.0:*:*:*:*:windows_communication_foundation:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C5C3D32-B556-4497-845A-7EFCB79C592A"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_management_agent:1.2.0:*:*:*:*:websphere:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA3EE86D-3D3F-4E28-A561-27419534AD92"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_management_agent:1.2.0:*:*:*:*:windows_communication_foundation:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2BF92F9-1851-4EF2-808B-F12579C387F6"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_policy_agent:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26F541DE-7CF5-42F5-965D-844D765532CD"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_policy_agent:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2F85A68-A4C8-4F6C-AB15-66A96D6510CF"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_policy_agent:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BE04D58-1BAF-46D8-B9C5-B95F8E359275"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_policy_manager:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9464AF8-BBA8-4D83-B29E-DD51AF4F8074"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_policy_manager:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBBBC2BC-5F48-47DA-BDA4-BF7315512249"
            },
            {
              "criteria": "cpe:2.3:a:tibco:activematrix_policy_manager:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E72B7037-EC98-4F9A-8702-0B073AEC24A3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}