CVE-2014-6112: Infoleak
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sensitive information by leveraging support for weak SSL ciphers. IBM X-Force ID: 96184.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2014-6112.
What is the severity of CVE-2014-6112?
The severity of CVE-2014-6112 is medium with a severity value of 5.9.
Which IBM products are affected by CVE-2014-6112?
IBM Tivoli Identity Manager versions 5.1.x, IBM Security Identity Manager versions 6.0.x and 7.0.x.
How can remote attackers exploit CVE-2014-6112?
Remote attackers can exploit CVE-2014-6112 by leveraging support for weak SSL ciphers to obtain sensitive information.
How can I fix CVE-2014-6112?
To fix CVE-2014-6112, upgrade to IBM Tivoli Identity Manager 5.1.0.15-ISS-TIM-IF0057, Security Identity Manager 6.0.0.4-ISS-SIM-IF0001, or 7.0.0.0-ISS-SIM-IF0003 to address the weak SSL cipher vulnerability.