Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3053


The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.


Published

2014-06-21T15:55:03.870

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 8.0 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:C/I:P/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: PARTIAL
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

9.5

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm security_access_manager_for_web_8.0_firmware 8.0.0.2 Yes
Operating System ibm security_access_manager_for_web_8.0_firmware 8.0.0.3 Yes
Hardware ibm security_access_manager_for_web_appliance 8.0 Yes
Application ibm security_access_manager_for_mobile_software 8.0 Yes
Application ibm security_access_manager_for_web_software 7.0 Yes
Application ibm security_access_manager_for_web_software 8.0 Yes
Hardware ibm security_access_manager_for_mobile_appliance 8.0 Yes
Hardware ibm security_access_manager_for_web_appliance 7.0 Yes
Hardware ibm security_access_manager_for_web_appliance 8.0 Yes

References