CVE-2014-6109: Infoleak
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via vectors related to server side LDAP queries. IBM X-Force ID: 96173.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability CVE-2014-6109 about?
The vulnerability CVE-2014-6109 is about IBM Tivoli Identity Manager and Security Identity Manager allowing remote authenticated users to bypass access restrictions and obtain sensitive information.
What is the severity of CVE-2014-6109?
The severity of CVE-2014-6109 is medium with a CVSS score of 5.3.
Which versions of IBM Tivoli Identity Manager are affected by CVE-2014-6109?
IBM Tivoli Identity Manager versions 5.1.x are affected by CVE-2014-6109.
Which versions of Security Identity Manager are affected by CVE-2014-6109?
Security Identity Manager versions 6.0.x and 7.0.x are affected by CVE-2014-6109.
How can I fix the vulnerability CVE-2014-6109?
To fix the vulnerability CVE-2014-6109, it is recommended to upgrade to IBM Tivoli Identity Manager 5.1.0.15-ISS-TIM-IF0057 or later, Security Identity Manager 6.0.0.4-ISS-SIM-IF0001 or later, or Security Identity Manager 7.0.0.0-ISS-SIM-IF0003 or later.