First published: Thu Dec 18 2014(Updated: )
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (disrupted system operations) by uploading a file to a protected area.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Web Firmware | =7.0 | |
IBM Security Access Manager for Web Firmware | =8.0 | |
IBM Security Access Manager for Mobile | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6089 is classified as a denial of service vulnerability that can disrupt system operations.
To mitigate CVE-2014-6089, it is recommended to upgrade IBM Security Access Manager for Mobile to version 8.0.1 and Security Access Manager for Web to version 7.0.0 FP10 or later.
CVE-2014-6089 affects users of IBM Security Access Manager for Web versions prior to 7.0.0 FP10 and IBM Security Access Manager for Mobile versions prior to 8.0.1.
Yes, CVE-2014-6089 can be exploited by remote authenticated users to cause a denial of service.
If impacted by CVE-2014-6089, you should immediately update your IBM Security Access Manager software to the latest recommended versions.