CVE-2014-6078: Medium severity ibm security access manager for mobile vulnerability
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6078?
CVE-2014-6078 is considered a high-severity vulnerability due to the risk of brute-force attacks leading to unauthorized admin access.
How do I fix CVE-2014-6078?
To fix CVE-2014-6078, you should update to IBM Security Access Manager for Mobile version 8.0.1 or Security Access Manager for Web version 7.0.0 FP10 or higher.
What is the main risk associated with CVE-2014-6078?
The main risk is that attackers can exploit the lack of a lockout period to perform brute-force login attempts, compromising administrator accounts.
Which versions are affected by CVE-2014-6078?
CVE-2014-6078 affects IBM Security Access Manager for Mobile versions before 8.0.1 and IBM Security Access Manager for Web versions before 7.0.0 FP10 and 8.0.1.
Is there a workaround for CVE-2014-6078?
While upgrading is the recommended solution, organizations can mitigate risks by implementing additional monitoring or throttling for login attempts.