First published: Thu Dec 18 2014(Updated: )
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive information by sniffing the network during use of the null SSL cipher.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Web Firmware | =7.0 | |
IBM Security Access Manager for Web Firmware | =8.0 | |
IBM Security Access Manager for Mobile | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6088 is rated as a medium severity vulnerability due to the potential for information disclosure.
To fix CVE-2014-6088, upgrade to IBM Security Access Manager for Mobile version 8.0.1 or IBM Security Access Manager for Web version 7.0.0 FP10 or higher.
CVE-2014-6088 is an information disclosure vulnerability related to the use of a null SSL cipher.
CVE-2014-6088 affects users of IBM Security Access Manager for Mobile version 8.x and IBM Security Access Manager for Web versions 7.x and 8.x before specified fixes.
Attackers can exploit CVE-2014-6088 by sniffing unencrypted network traffic to gain access to sensitive information.