First published: Thu Dec 18 2014(Updated: )
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Mobile | =8.0 | |
IBM Security Access Manager for Web Firmware | =7.0 | |
IBM Security Access Manager for Web Firmware | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6080 has a high severity rating due to its SQL injection capabilities.
To fix CVE-2014-6080, upgrade to IBM Security Access Manager for Mobile version 8.0.1 or Security Access Manager for Web version 7.0.0 FP10 or later.
CVE-2014-6080 affects IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1.
CVE-2014-6080 enables remote authenticated users to execute arbitrary SQL commands.
Yes, CVE-2014-6080 can be exploited remotely by authenticated users.