CVE-2014-3052

IBM Security Access Manager (ISAM) for Web <8.0.0.2/3 - Info Disclo...

Title source: llm
STIX 2.1

Description

The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that lack NIST SP 800-131A compliance.

References (3)

Core 3
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21676705
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV61553
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/93454

Scores

EPSS 0.0036
EPSS Percentile 28.9%

Details

CWE
CWE-16
Status published
Products (3)
ibm/security_access_manager_for_web_8.0_firmware 8.0.0.2
ibm/security_access_manager_for_web_8.0_firmware 8.0.0.3
ibm/security_access_manager_for_web_appliance 8.0
Published Jun 21, 2014
Tracked Since Feb 18, 2026