CVE-2014-6107: Infoleak
Published Nov 18, 2014
·Updated
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
Affected Software
4 affected components
IBM Security Identity Manager=6.0.0.0
IBM Security Identity Manager=6.0.0.1
IBM Security Identity Manager=6.0.0.2
IBM Security Identity Manager=6.0.0.3
Event History
Nov 18, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6107?
CVE-2014-6107 is rated as a moderate severity vulnerability due to the potential exposure of sensitive cookie information.
2
How do I fix CVE-2014-6107?
To fix CVE-2014-6107, upgrade IBM Security Identity Manager to version 6.0.0.3 or later.
3
Who is affected by CVE-2014-6107?
CVE-2014-6107 affects users of IBM Security Identity Manager versions 6.0.0.0 to 6.0.0.2.
4
What kind of attack does CVE-2014-6107 enable?
CVE-2014-6107 enables remote attackers to obtain sensitive data via network sniffing during an HTTP session.
5
Is CVE-2014-6107 a client or server-side vulnerability?
CVE-2014-6107 is a server-side vulnerability affecting the IBM Security Identity Manager.