CVE-2014-6086: Infoleak
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure that HTTPS is used, which allows remote attackers to obtain sensitive information by sniffing the network during an HTTP session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6086?
CVE-2014-6086 is considered a medium severity vulnerability due to the risk of sensitive information exposure over unencrypted HTTP.
How do I fix CVE-2014-6086?
To fix CVE-2014-6086, ensure that your IBM Security Access Manager for Mobile 8.x and Security Access Manager for Web 7.x or 8.x are configured to utilize HTTPS for all sessions.
What systems are affected by CVE-2014-6086?
CVE-2014-6086 affects IBM Security Access Manager for Mobile 8.x (before 8.0.1) and Security Access Manager for Web 7.x (before 7.0.0 FP10) and 8.x (before 8.0.1).
What type of attacks can exploit CVE-2014-6086?
Attackers can exploit CVE-2014-6086 through network sniffing to intercept sensitive information during HTTP sessions.
What are the primary risks associated with CVE-2014-6086?
The primary risks associated with CVE-2014-6086 include unauthorized access to sensitive data and potential data leakage during unencrypted communication.