CVE-2014-6098: Medium severity ibm security identity manager vulnerability
Published Nov 18, 2014
·Updated
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request.
Affected Software
4 affected components
IBM Security Identity Manager=6.0.0.0
IBM Security Identity Manager=6.0.0.1
IBM Security Identity Manager=6.0.0.2
IBM Security Identity Manager=6.0.0.3
Event History
Nov 18, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6098?
CVE-2014-6098 has a medium severity rating due to its potential to expose cleartext passwords.
2
How do I fix CVE-2014-6098?
To fix CVE-2014-6098, upgrade to IBM Security Identity Manager version 6.0.0.3 or later.
3
Who is affected by CVE-2014-6098?
CVE-2014-6098 affects users of IBM Security Identity Manager versions 6.0.0.0 through 6.0.0.2.
4
What type of attack does CVE-2014-6098 allow?
CVE-2014-6098 allows remote attackers to discover cleartext passwords through crafted requests.
5
When was CVE-2014-6098 disclosed?
CVE-2014-6098 was disclosed in 2014, highlighting vulnerabilities in earlier versions of IBM Security Identity Manager.