IBM Security Identity Manager CVE-2014-6110 Local Security Bypass Vulnerability
BID:71114
Info
IBM Security Identity Manager CVE-2014-6110 Local Security Bypass Vulnerability
| Bugtraq ID: | 71114 |
| Class: | Design Error |
| CVE: |
CVE-2014-6110 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 13 2014 12:00AM |
| Updated: | Nov 13 2014 12:00AM |
| Credit: | Paul Ionescu, Brennan Brazeau, John Zuccato, Jonathan Fitz-Gerald, and Warren Moynihan. |
| Vulnerable: |
IBM Security Identity Manager 6.0 |
| Not Vulnerable: | |
Discussion
IBM Security Identity Manager CVE-2014-6110 Local Security Bypass Vulnerability
IBM Security Identity Manager is prone to a local security-bypass vulnerability.
Successful exploits will allow local attackers to bypass certain security restrictions. Other attacks are also possible.
IBM Security Identity Manager 6.0 is vulnerable.
IBM Security Identity Manager is prone to a local security-bypass vulnerability.
Successful exploits will allow local attackers to bypass certain security restrictions. Other attacks are also possible.
IBM Security Identity Manager 6.0 is vulnerable.
Exploit / POC
IBM Security Identity Manager CVE-2014-6110 Local Security Bypass Vulnerability
Attackers require local interactive access to exploit this issue.
Attackers require local interactive access to exploit this issue.
Solution / Fix
IBM Security Identity Manager CVE-2014-6110 Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.