CVE-2014-8895
Status: ModifiedMedium (4.3)—
IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.24%
- Percentile among all scored CVEs: 68
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-264
References
- http://secunia.com/advisories/62674
- http://www-01.ibm.com/support/docview.wss?uid=swg21694771
- http://www.securityfocus.com/bid/72430
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99014
- http://secunia.com/advisories/62674
- http://www-01.ibm.com/support/docview.wss?uid=swg21694771
- http://www.securityfocus.com/bid/72430
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99014
Raw JSON (NVD)
Show
{
"id": "CVE-2014-8895",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-01-29T01:59:02.577",
"references": [
{
"url": "http://secunia.com/advisories/62674",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21694771",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securityfocus.com/bid/72430",
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99014",
"source": "psirt@us.ibm.com"
},
{
"url": "http://secunia.com/advisories/62674",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21694771",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/72430",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99014",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL."
},
{
"lang": "es",
"value": "IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 anterior a 3.3.2.3, y 3.4.1 anterior a 3.4.1.1 permite a atacantes remotos evadir las restricciones de acceso y leer los ficheros de imágenes de usuarios arbitrarios a través de una URL manipulada."
}
],
"lastModified": "2026-06-17T00:17:29.973",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46D0A920-F5D2-4FB7-8EF1-E892B27F3158"
},
{
"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "110B75DA-3B5D-4B2A-A243-C02F04A69DD8"
},
{
"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CFF6D9D-633A-414B-9A81-9627F1006F99"
},
{
"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97EB5F4E-24BB-4F17-80B1-963DBC66E44D"
},
{
"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC985F26-E915-49CA-951A-7E3FE59E5377"
},
{
"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4271E1DA-B047-4C91-93D6-EF5A9EE9AC51"
},
{
"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27D8FE59-90C3-4EE3-BA70-01C71DCC27B0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}