CVE-2014-3053
Summary
| CVE | CVE-2014-3053 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-21 15:55:00 UTC |
| Updated | 2017-08-29 01:34:00 UTC |
| Description | The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: IBM Security Access Manager for Mobile and IBM Security Access Manager for Web appliances - LMI Authentication Bypass (CVE-2014-3053) - United States | CONFIRM | www-01.ibm.com | Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-01.ibm.com | |
| Security Advisory SA59438 - IBM Security Access Manager for Web / Security Access Manager for Mobile Multiple Vulnerabilities - Secunia | SECUNIA | secunia.com | |
| Security Advisory SA59381 - IBM Security Privileged Identity Manager LMI Authentication Bypass Vulnerability - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM Security Access Manager for Web and Mobile CVE-2014-3053 Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| Security Bulletin: IBM Security Privileged Identity Manager virtual appliance - LMI Authentication Bypass (CVE-2014-3053) | CONFIRM | www-01.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.