CVE-2014-4809: High severity ibm security access manager for web 8.0 vulnerability
The WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, when e-community SSO is enabled, allows remote attackers to cause a denial of service (component hang) via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4809?
CVE-2014-4809 is classified as a denial of service vulnerability that can cause component hang.
How do I fix CVE-2014-4809?
To fix CVE-2014-4809, apply the latest fix pack or interim fix for IBM Security Access Manager for Web, specifically versions 7.0.0-ISS-WGA-IF0009 or 8.0.0-ISS-WGA-FP0005 and above.
What components are affected by CVE-2014-4809?
CVE-2014-4809 affects the WebSEAL component of IBM Security Access Manager for Web versions 7.x and 8.x.
Can CVE-2014-4809 be exploited remotely?
Yes, CVE-2014-4809 can be exploited remotely by attackers if e-community SSO is enabled.
What impact does CVE-2014-4809 have on systems?
CVE-2014-4809 can lead to a denial of service, effectively causing the affected WebSEAL component to become unresponsive.