First published: Fri Aug 22 2014(Updated: )
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3070 is considered a medium severity vulnerability due to its potential for unauthorized access.
To fix CVE-2014-3070, you should update IBM WebSphere Application Server to version 8.0.0.10 or 8.5.5.3 or later.
CVE-2014-3070 affects IBM WebSphere Application Server versions 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3.
Yes, CVE-2014-3070 can be exploited remotely by attackers to bypass access restrictions.
CVE-2014-3070 involves a flaw in the addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task that improperly creates accounts.