4
CVSSv2

CVE-2014-1682

Published: 08/05/2014 Updated: 09/05/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The API in Zabbix prior to 1.8.20rc1, 2.0.x prior to 2.0.11rc1, and 2.2.x prior to 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 2.0.2

zabbix zabbix 2.0.3

zabbix zabbix 2.0.7

zabbix zabbix 2.0.8

zabbix zabbix 2.2.0

zabbix zabbix 2.2.1

zabbix zabbix 2.0.0

zabbix zabbix 2.0.1

zabbix zabbix 2.0.5

zabbix zabbix 1.8

zabbix zabbix 1.8.3

zabbix zabbix 2.0.9

zabbix zabbix 2.0.10

zabbix zabbix 2.0.4

fedoraproject fedora 19

fedoraproject fedora 20

zabbix zabbix 2.0.6

zabbix zabbix 1.8.15

zabbix zabbix 1.8.16

zabbix zabbix 1.8.18

zabbix zabbix

zabbix zabbix 1.8.1

zabbix zabbix 1.8.2

Vendor Advisories

Debian Bug report logs - #737818 zabbix: CVE-2014-1682: API issue allows users to impersonate other users Package: src:zabbix; Maintainer for src:zabbix is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Feb 2014 07:42:06 UTC Severity: grave Tags: security, ups ...