CVE-2014-6088: Infoleak
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive information by sniffing the network during use of the null SSL cipher.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6088?
CVE-2014-6088 is rated as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2014-6088?
To fix CVE-2014-6088, upgrade to IBM Security Access Manager for Mobile version 8.0.1 or IBM Security Access Manager for Web version 7.0.0 FP10 or higher.
What type of vulnerability is CVE-2014-6088?
CVE-2014-6088 is an information disclosure vulnerability related to the use of a null SSL cipher.
Who is affected by CVE-2014-6088?
CVE-2014-6088 affects users of IBM Security Access Manager for Mobile version 8.x and IBM Security Access Manager for Web versions 7.x and 8.x before specified fixes.
How can attackers exploit CVE-2014-6088?
Attackers can exploit CVE-2014-6088 by sniffing unencrypted network traffic to gain access to sensitive information.