CVE-2014-6108: Infoleak
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middle attackers to obtain sensitive information by leveraging an unencrypted connection for interfaces. IBM X-Force ID: 96172.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-6108?
CVE-2014-6108 refers to a vulnerability in IBM Tivoli Identity Manager and Security Identity Manager that allows man-in-the-middle attackers to obtain sensitive information.
How does CVE-2014-6108 affect IBM Tivoli Identity Manager?
CVE-2014-6108 affects IBM Tivoli Identity Manager versions 5.1.x before 5.1.0.15-ISS-TIM-IF0057.
How does CVE-2014-6108 affect Security Identity Manager?
CVE-2014-6108 affects Security Identity Manager versions 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003.
What is the severity of CVE-2014-6108?
CVE-2014-6108 has a severity value of 5.9, which is considered medium.
How do I fix CVE-2014-6108?
To fix CVE-2014-6108, upgrade IBM Tivoli Identity Manager to version 5.1.0.15-ISS-TIM-IF0057 or higher, or upgrade Security Identity Manager to version 6.0.0.4-ISS-SIM-IF0001 or 7.0.0.0-ISS-SIM-IF0003 or higher.