CVE-2014-4823: OS Command Injection
The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4823?
CVE-2014-4823 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2014-4823?
To fix CVE-2014-4823, upgrade IBM Security Access Manager for Web to version 7.0.0-ISS-WGA-IF0009 or 8.0.0-ISS-WGA-FP0005 or higher.
What software is affected by CVE-2014-4823?
CVE-2014-4823 affects IBM Security Access Manager for Web versions 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005.
What types of attacks can CVE-2014-4823 facilitate?
CVE-2014-4823 can facilitate remote command injection attacks, allowing attackers to execute arbitrary system commands.
Who is vulnerable to CVE-2014-4823?
Organizations using affected versions of IBM Security Access Manager for Web or Mobile are vulnerable to CVE-2014-4823.