CVE-2014-3053: High severity ibm security access manager for web 8.0 vulnerability
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3053?
CVE-2014-3053 has a medium severity rating, indicating it poses a moderate risk for exploitation.
How do I fix CVE-2014-3053?
To fix CVE-2014-3053, upgrade IBM Security Access Manager to versions 8.0.0.4 or later for affected installations.
What systems are affected by CVE-2014-3053?
CVE-2014-3053 affects IBM Security Access Manager for Web version 7.0 and 8.0 with specific firmware versions, as well as IBM Security Access Manager for Mobile 8.0.
Can CVE-2014-3053 allow unauthorized access?
Yes, CVE-2014-3053 can allow remote attackers to bypass authentication and gain unauthorized access.
Is there a workaround for CVE-2014-3053 if I can't immediately upgrade?
As of the identification of CVE-2014-3053, no specific workaround is provided; upgrading to the latest version is recommended.