Vulnerability Description
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to login to arbitrary domain accounts by using the corresponding username on a Windows client machine.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ontariosystems | Artiva Architect | 3.2 |
| Ontariosystems | Artiva Healthcare | 5.2 |
| Ontariosystems | Artiva Rm | 3.1 |
| Ontariosystems | Artiva Workstation | 1.3.0 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/215284US Government Resource
- http://www.kb.cert.org/vuls/id/215284US Government Resource
FAQ
What is CVE-2014-0348?
CVE-2014-0348 is a vulnerability with a CVSS score of 3.5 (LOW). The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option ...
How severe is CVE-2014-0348?
CVE-2014-0348 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0348?
Check the references section above for vendor advisories and patch information. Affected products include: Ontariosystems Artiva Architect, Ontariosystems Artiva Healthcare, Ontariosystems Artiva Rm, Ontariosystems Artiva Workstation.