← Vulnerability feed

Vulnerability record · CVE-2014-6120 · published 12 April 2018

CVE-2014-6120: Ibm rational appscan source command injection vulnerability

Ibm · Rational Appscan Source

IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721.

9.8 CVSS 3.0 Critical EPSS 5.0% · top 8.0% CWE-77 · Command injection
9.8CVSS 3.0 base score, v2 10.0
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-6120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-6119Ibm security appscan code injection vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 3.6%7.2CVE-2014-3072Ibm security appscan source vulnerabilityUnspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 th…EPSS 0.37%5.8CVE-2012-2159Ibm security appscan source improper input validation vulnerabilityOpen redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collec…EPSS 1.8%5.5CVE-2014-6122Ibm security appscan permissions and access controls vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 1.5%5.3CVE-2016-3035Ibm security appscan source information exposure vulnerabilityIBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.EPSS 1.0%5.0CVE-2012-2173Ibm security appscan source vulnerabilityThe ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB …EPSS 1.2%4.4CVE-2016-3034Ibm security appscan source inadequate encryption strength vulnerabilityIBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt informatio…EPSS 0.21%4.3CVE-2014-6135Ibm security appscan improper input validation vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2014-6120), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.