CVE-2014-0963: High severity IBM Security Access Manager For Web Software vulnerability
The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0963?
CVE-2014-0963 is classified as a denial of service vulnerability that can cause an infinite loop.
How do I fix CVE-2014-0963?
To resolve CVE-2014-0963, update to IBM Security Access Manager for Web version 7.0.0-ISS-SAM-IF0006 or 8.0.0.3-ISS-WGA-IF0002 or later.
What products are affected by CVE-2014-0963?
CVE-2014-0963 affects IBM Security Access Manager for Web versions 7.0 and 8.0, as well as the corresponding appliance versions.
Can CVE-2014-0963 be exploited remotely?
Yes, CVE-2014-0963 can be exploited remotely by sending crafted SSL messages.
What type of vulnerability is CVE-2014-0963?
CVE-2014-0963 is a denial of service vulnerability related to the Reverse Proxy feature in IBM GSKit.