CVE-2014-2536
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
18/03/2014
Last modified:
12/04/2025
Description
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown vectors.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:intel:expressway_cloud_access_360:2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:intel:expressway_cloud_access_360:2.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mcafee:cloud_identity_manager:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mcafee:cloud_identity_manager:3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mcafee:cloud_identity_manager:3.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mcafee:cloud_single_sign_on:4.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/57368
- http://secunia.com/advisories/57381
- http://www.securityfocus.com/bid/66181
- https://kc.mcafee.com/corporate/index?page=content&id=SB10066
- http://secunia.com/advisories/57368
- http://secunia.com/advisories/57381
- http://www.securityfocus.com/bid/66181
- https://kc.mcafee.com/corporate/index?page=content&id=SB10066



