« Back to list

CVE-2014-6309

Status: ModifiedHigh (7.5)—

The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2014-6309",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-04-12T15:29:00.210",
  "references": [
    {
      "url": "https://support.kaazing.com/hc/en-us/articles/115004550547-Advisory-for-KGS-879",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.tenefit.com/hc/en-us/articles/115004550547-Advisory-for-KGS-879",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://support.kaazing.com/hc/en-us/articles/115004550547-Advisory-for-KGS-879",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling."
    },
    {
      "lang": "es",
      "value": "Los componentes del motor HTTP y WebSocket en el servidor en Kaazing Gateway 4.0.2, 4.0.3 y 4.0.4; y Gateway - JMS Edition 4.0.2, 4.0.3 y 4.0.4 permiten que atacantes remotos obtengan información sensible mediante vectores relacionados con la gestión de peticiones HTTP."
    }
  ],
  "lastModified": "2026-06-17T00:12:53.153",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94170050-0C11-4E80-9997-ABA920CE75DB"
            },
            {
              "criteria": "cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6389D192-7630-4BA1-8D7A-917BBDF18D2A"
            },
            {
              "criteria": "cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D56842C4-AC7B-4E0E-B929-42B7EEED24EB"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.2:*:*:*:jms:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7866DB7-6037-4DF7-880C-4A6AEAF03D4C"
            },
            {
              "criteria": "cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.3:*:*:*:jms:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBE04E79-EE8A-4CDE-94B5-A04074D5CEE6"
            },
            {
              "criteria": "cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.4:*:*:*:jms:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D61AE456-F7D8-4AA0-A22D-CAC793248595"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}