Lucene search

K
cveIbmCVE-2014-3053
HistoryJun 21, 2014 - 3:55 p.m.

CVE-2014-3053

2014-06-2115:55:03
CWE-287
ibm
web.nvd.nist.gov
17
ibm security access manager
isam
lmi
cve-2014-3053
bypass authentication
firmware vulnerability

CVSS2

8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:P/A:C

AI Score

7

Confidence

Low

EPSS

0.009

Percentile

82.3%

The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.

Affected configurations

Nvd
Node
ibmsecurity_access_manager_for_web_8.0_firmwareMatch8.0.0.2
OR
ibmsecurity_access_manager_for_web_8.0_firmwareMatch8.0.0.3
AND
ibmsecurity_access_manager_for_web_applianceMatch8.0
Node
ibmsecurity_access_manager_for_mobile_softwareMatch8.0
OR
ibmsecurity_access_manager_for_web_softwareMatch7.0
OR
ibmsecurity_access_manager_for_web_softwareMatch8.0
OR
ibmsecurity_access_manager_for_mobile_applianceMatch8.0
OR
ibmsecurity_access_manager_for_web_applianceMatch7.0
OR
ibmsecurity_access_manager_for_web_applianceMatch8.0
VendorProductVersionCPE
ibmsecurity_access_manager_for_web_8.0_firmware8.0.0.2cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.2:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_web_8.0_firmware8.0.0.3cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.3:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_web_appliance8.0cpe:2.3:h:ibm:security_access_manager_for_web_appliance:8.0:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile_software8.0cpe:2.3:a:ibm:security_access_manager_for_mobile_software:8.0:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_web_software7.0cpe:2.3:a:ibm:security_access_manager_for_web_software:7.0:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_web_software8.0cpe:2.3:a:ibm:security_access_manager_for_web_software:8.0:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile_appliance8.0cpe:2.3:h:ibm:security_access_manager_for_mobile_appliance:8.0:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_web_appliance7.0cpe:2.3:h:ibm:security_access_manager_for_web_appliance:7.0:*:*:*:*:*:*:*

CVSS2

8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:P/A:C

AI Score

7

Confidence

Low

EPSS

0.009

Percentile

82.3%

Related for CVE-2014-3053