{"api_version":"1","generated_at":"2026-07-23T09:12:25+00:00","cve":"CVE-2014-3036","urls":{"html":"https://cve.report/CVE-2014-3036","api":"https://cve.report/api/cve/CVE-2014-3036.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-3036","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-3036"},"summary":{"title":"CVE-2014-3036","description":"Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attackers to bypass intended restrictions on topology access, and obtain sensitive information, via unknown vectors.","state":"PUBLISHED","assigner":"ibm","published_at":"2014-06-08 23:55:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/59044","name":"http://secunia.com/advisories/59044","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA59044 - IBM API Management Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/67941","name":"http://www.securityfocus.com/bid/67941","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM API Management CVE-2014-3036 Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21674232","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21674232","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1LI78000","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1LI78000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93302","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93302","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-3036","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3036","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"3036","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"api_management","cpe6":"3.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:28:46.363Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"67941","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/67941"},{"name":"ibm-api-cve20143036-info-disc(93302)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93302"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21674232"},{"name":"59044","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59044"},{"name":"LI78000","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1LI78000"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-06-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attackers to bypass intended restrictions on topology access, and obtain sensitive information, via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"67941","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/67941"},{"name":"ibm-api-cve20143036-info-disc(93302)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93302"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21674232"},{"name":"59044","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59044"},{"name":"LI78000","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1LI78000"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2014-3036","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attackers to bypass intended restrictions on topology access, and obtain sensitive information, via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"67941","refsource":"BID","url":"http://www.securityfocus.com/bid/67941"},{"name":"ibm-api-cve20143036-info-disc(93302)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93302"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21674232","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21674232"},{"name":"59044","refsource":"SECUNIA","url":"http://secunia.com/advisories/59044"},{"name":"LI78000","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1LI78000"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2014-3036","datePublished":"2014-06-08T23:00:00.000Z","dateReserved":"2014-04-29T00:00:00.000Z","dateUpdated":"2024-08-06T10:28:46.363Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-06-08 23:55:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:api_management:3.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"FDCDCF24-B490-4FF1-BFA2-9922EFF9F0C2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"3036","Ordinal":"1","Title":"CVE-2014-3036","CVE":"CVE-2014-3036","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"3036","Ordinal":"1","NoteData":"Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attackers to bypass intended restrictions on topology access, and obtain sensitive information, via unknown vectors.","Type":"Description","Title":"CVE-2014-3036"},{"CveYear":"2014","CveId":"3036","Ordinal":"2","NoteData":"2014-06-08","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"3036","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}