First published: Sat Jun 21 2014(Updated: )
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Web 8.0 | =8.0.0.2 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.3 | |
IBM Security Access Manager for Web | =8.0 | |
IBM Security Access Manager for Mobile | =8.0 | |
IBM Security Access Manager for Web | =7.0 | |
IBM Security Access Manager for Web | =8.0 | |
IBM Security Access Manager for Mobile Appliance | =8.0 | |
IBM Security Access Manager for Web | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3053 has a medium severity rating, indicating it poses a moderate risk for exploitation.
To fix CVE-2014-3053, upgrade IBM Security Access Manager to versions 8.0.0.4 or later for affected installations.
CVE-2014-3053 affects IBM Security Access Manager for Web version 7.0 and 8.0 with specific firmware versions, as well as IBM Security Access Manager for Mobile 8.0.
Yes, CVE-2014-3053 can allow remote attackers to bypass authentication and gain unauthorized access.
As of the identification of CVE-2014-3053, no specific workaround is provided; upgrading to the latest version is recommended.