CVE-2014-0348

low
Published 2014-04-15 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to login to arbitrary domain accounts by using the corresponding username on a Windows client machine.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
ontariosystemsartiva_architect3.2
ontariosystemsartiva_healthcare5.2
ontariosystemsartiva_rm3.1
ontariosystemsartiva_workstation1.3.0

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.