First published: Thu Dec 18 2014(Updated: )
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Mobile | =8.0 | |
IBM Security Access Manager for Web Firmware | =7.0 | |
IBM Security Access Manager for Web Firmware | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6078 is considered a high-severity vulnerability due to the risk of brute-force attacks leading to unauthorized admin access.
To fix CVE-2014-6078, you should update to IBM Security Access Manager for Mobile version 8.0.1 or Security Access Manager for Web version 7.0.0 FP10 or higher.
The main risk is that attackers can exploit the lack of a lockout period to perform brute-force login attempts, compromising administrator accounts.
CVE-2014-6078 affects IBM Security Access Manager for Mobile versions before 8.0.1 and IBM Security Access Manager for Web versions before 7.0.0 FP10 and 8.0.1.
While upgrading is the recommended solution, organizations can mitigate risks by implementing additional monitoring or throttling for login attempts.