CVE-2014-6105: Input Validation
Published Nov 18, 2014
·Updated
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Affected Software
4 affected components
IBM Security Identity Manager=6.0.0.0
IBM Security Identity Manager=6.0.0.1
IBM Security Identity Manager=6.0.0.2
IBM Security Identity Manager=6.0.0.3
Event History
Nov 18, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6105?
CVE-2014-6105 has a medium severity rating due to its potential to allow clickjacking attacks.
2
How do I fix CVE-2014-6105?
To mitigate CVE-2014-6105, upgrade to IBM Security Identity Manager version 6.0.0.3 or later.
3
What versions of IBM Security Identity Manager are affected by CVE-2014-6105?
IBM Security Identity Manager versions 6.0.0.0, 6.0.0.1, and 6.0.0.2 are affected by CVE-2014-6105.
4
What are the potential impacts of CVE-2014-6105?
CVE-2014-6105 can lead to unauthorized actions being performed on behalf of users through clickjacking.
5
Is there a workaround for CVE-2014-6105 if I cannot update immediately?
There is no official workaround for CVE-2014-6105; the best option is to apply the available patch as soon as possible.