Vulnerability Name: | CVE-2014-3053 (CCN-93501) | ||||||||
Assigned: | 2014-06-19 | ||||||||
Published: | 2014-06-19 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials. | ||||||||
CVSS v3 Severity: | 8.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H)
| ||||||||
CVSS v2 Severity: | 8.0 High (CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:P/A:C) 5.9 Medium (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:P/A:C/E:U/RL:OF/RC:C)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:P/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3053 Source: SECUNIA Type: UNKNOWN 59381 Source: SECUNIA Type: UNKNOWN 59438 Source: AIXAPAR Type: UNKNOWN IV61557 Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?uid=swg21676389 Source: CCN Type: IBM Security Bulletin 1676700 IBM Security Access Manager for Mobile and IBM Security Access Manager for Web appliances - LMI Authentication Bypass (CVE-2014-3053) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21676700 Source: BID Type: UNKNOWN 68132 Source: CCN Type: BID-68132 IBM Security Access Manager for Web and Mobile CVE-2014-3053 Authentication Bypass Vulnerability Source: XF Type: UNKNOWN ibm-mesa-cve20143053-sec-bypass(93501) Source: XF Type: UNKNOWN ibm-isam-cve20143053-credentials(93501) Source: CCN Type: IBM Security Bulletin 1676389 IBM Security Privileged Identity Manager virtual appliance - LMI Authentication Bypass (CVE-2014-3053) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |