5.5
CVSSv2

CVE-2014-1685

Published: 08/05/2014 Updated: 09/05/2014
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

The Frontend in Zabbix prior to 1.8.20rc2, 2.0.x prior to 2.0.11rc2, and 2.2.x prior to 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 2.0.2

zabbix zabbix 2.0.3

zabbix zabbix 2.2.1

zabbix zabbix 2.2.0

zabbix zabbix 2.0.4

zabbix zabbix 2.0.5

zabbix zabbix 2.0.6

zabbix zabbix 1.8

zabbix zabbix 2.0.7

zabbix zabbix 2.0.8

zabbix zabbix 2.0.0

zabbix zabbix 2.0.1

zabbix zabbix

zabbix zabbix 1.8.2

zabbix zabbix 1.8.3

zabbix zabbix 2.0.9

zabbix zabbix 2.0.10

zabbix zabbix 1.8.1

zabbix zabbix 1.8.16

fedoraproject fedora 19

zabbix zabbix 1.8.15

zabbix zabbix 1.8.18

fedoraproject fedora 20

Vendor Advisories

Debian Bug report logs - #737818 zabbix: CVE-2014-1682: API issue allows users to impersonate other users Package: src:zabbix; Maintainer for src:zabbix is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Feb 2014 07:42:06 UTC Severity: grave Tags: security, ups ...