CVE-2015-6745
Estado: ModificadaMedia (4.6)—
Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6744.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 4.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-6745",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-08-31T14:59:04.900",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2015/Jul/120",
"source": "cve@mitre.org"
},
{
"url": "https://www.viestintavirasto.fi/en/cybersecurity/vulnerabilities/2015/haavoittuvuus-2015-018.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2015/Jul/120",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.viestintavirasto.fi/en/cybersecurity/vulnerabilities/2015/haavoittuvuus-2015-018.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6744."
},
{
"lang": "es",
"value": "Vulnerabilidad en Basware Banking (Maksuliikenne) 8.90.07.X, confía en el cliente para hacer cumplir el bloqueo de cuenta, lo que permite a usuarios locales evadir este mecanismo de seguridad mediante la supresión de la tabla de bloqueo. NOTA: este identificador fue SEPARADO de CVE-2015-0942 por ADT2 y ADT3 debido a los diferentes tipos de vulnerabilidades y diferentes versiones afectadas. NOTA: esta vulnerabilidad existe debido a una solución incorrecta para CVE-2015-6744."
}
],
"lastModified": "2026-06-17T00:31:21.100",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:basware:banking:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35D5DDC9-E7FE-4699-9FF7-B6EFCB2E07BF",
"versionEndIncluding": "8.90.07"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}