« Volver al listado

CVE-2014-5504

Estado: ModificadaAlta (7.5)—

SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via unspecified vectors, related to HyperSQL.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-5504",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-09-04T17:55:08.467",
  "references": [
    {
      "url": "http://www.solarwinds.com/documentation/lem/docs/releasenotes/releasenotes.htm",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-14-303/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.solarwinds.com/documentation/lem/docs/releasenotes/releasenotes.htm",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-14-303/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SolarWinds Log and Event Manager before 6.0 uses \"static\" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via unspecified vectors, related to HyperSQL."
    },
    {
      "lang": "es",
      "value": "SolarWinds Log And Event Manager anterior a 6.0 utiliza credenciales 'estáticas', lo que facilita a atacantes remotos obtener acceso a la base de datos y ejecutar código arbitrario a través de vectores no especificados, relacionado con HyperSQL."
    }
  ],
  "lastModified": "2026-06-17T00:11:37.800",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:solarwinds:log_and_event_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97D16E76-A32B-47DF-BB11-7404526FF1FA",
              "versionEndIncluding": "5.7.0"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:log_and_event_manager:5.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB5D00CB-0F36-45EC-B72A-51ACAC05B62C"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:log_and_event_manager:5.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F2A977A-0A83-4672-9DCB-5C137B15AE64"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:log_and_event_manager:5.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2098D634-C2F5-4DEF-86DB-483BF860D1CF"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:log_and_event_manager:5.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F1B9FF2-BAA4-4FB6-940F-E08F5F380578"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}