VYPR
Unrated severityNVD Advisory· Published Jun 24, 2015· Updated Jun 17, 2026

CVE-2014-4875

CVE-2014-4875

Description

CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Toshiba/Chec3 versions
    cpe:2.3:a:toshiba:chec:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:toshiba:chec:*:*:*:*:*:*:*:*range: <=6.6
    • cpe:2.3:a:toshiba:chec:6.7:*:*:*:*:*:*:*
    • (no CPE)range: <=6.6 build 4014 und 6.7<build 4329

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.