CVE-2014-3070: Medium severity ibm websphere application server feature pack for web services vulnerability
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3070?
CVE-2014-3070 is considered a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2014-3070?
To fix CVE-2014-3070, you should update IBM WebSphere Application Server to version 8.0.0.10 or 8.5.5.3 or later.
What versions of IBM WebSphere Application Server are affected by CVE-2014-3070?
CVE-2014-3070 affects IBM WebSphere Application Server versions 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3.
Can CVE-2014-3070 be exploited remotely?
Yes, CVE-2014-3070 can be exploited remotely by attackers to bypass access restrictions.
What is the nature of the vulnerability described in CVE-2014-3070?
CVE-2014-3070 involves a flaw in the addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task that improperly creates accounts.