CVE-2014-3053
Summary
| CVE | CVE-2014-3053 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-21 15:55:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
PartialAvailability
CompleteAV:A/AC:L/Au:N/C:C/I:P/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ibm | Security Access Manager For Mobile Appliance | 8.0 | All | All | All |
| Application | Ibm | Security Access Manager For Mobile Software | 8.0 | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.2 | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.3 | All | All | All |
| Hardware | Ibm | Security Access Manager For Web Appliance | 7.0 | All | All | All |
| Hardware | Ibm | Security Access Manager For Web Appliance | 8.0 | All | All | All |
| Application | Ibm | Security Access Manager For Web Software | 7.0 | All | All | All |
| Application | Ibm | Security Access Manager For Web Software | 8.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM Security Access Manager for Web and Mobile CVE-2014-3053 Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Security Bulletin: IBM Security Access Manager for Mobile and IBM Security Access Manager for Web appliances - LMI Authentication Bypass (CVE-2014-3053) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| Security Advisory SA59381 - IBM Security Privileged Identity Manager LMI Authentication Bypass Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Bulletin: IBM Security Privileged Identity Manager virtual appliance - LMI Authentication Bypass (CVE-2014-3053) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Security Advisory SA59438 - IBM Security Access Manager for Web / Security Access Manager for Mobile Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.