Show plain JSON{"id": "CVE-2015-4990", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 1.9, "accessVector": "LOCAL", "vectorString": "AV:L/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 3.4, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 4.0, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "REQUIRED", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "HIGH", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 0.3}]}, "published": "2016-01-02T05:59:01.580", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21969739", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-200"}]}], "descriptions": [{"lang": "en", "value": "The portal in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows local users to discover credentials by leveraging privileges during an unspecified connection type."}, {"lang": "es", "value": "El portal en IBM Tealeaf Customer Experience en versiones anteriores a 8.7.1.8818, 8.8 en versiones anteriores a 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 en versiones anteriores a 9.0.1.1083, 9.0.1A en versiones anteriores a 9.0.1.5073, 9.0.2 en versiones anteriores a 9.0.2.1095 y 9.0.2A en versiones anteriores a 9.0.2.5144 permite a usuarios locales descubrir credenciales aprovechando privilegios durante un tipo de conexi\u00f3n no especificada."}], "lastModified": "2016-01-06T18:58:35.117", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06154DF2-11C1-4D1E-8FD2-30258CCDFA38", "versionEndIncluding": "8.6"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41B6A77E-1686-44A6-B1E4-AC63A0466AE2"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:8.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBAC9796-BA52-48AF-9326-3C2343BE2342"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:9.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D705DD1-8F24-49B4-8D05-F0403A625016"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:9.0.0a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A2BAB44-B859-4209-BAFD-088E9583F31B"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:9.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D66B990-2034-46D9-AF8D-DE69B3161F38"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:9.0.1a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50EC1311-629F-401B-9AE3-8ECDE0CBF330"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:9.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AFA47D5-AC5B-4A1B-83A6-EE5D49ECE489"}, {"criteria": "cpe:2.3:a:ibm:tealeaf_customer_experience:9.0.2a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5FE2E49-88CF-4D61-8097-B3146A47BAED"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}