CVE-2014-3052
IBM Security Access Manager (ISAM) for Web <8.0.0.2/3 - Info Disclo...
Title source: llmDescription
The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that lack NIST SP 800-131A compliance.
References (3)
Core 3
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21676705
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV61553
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/93454
Scores
EPSS
0.0036
EPSS Percentile
28.9%
Details
CWE
CWE-16
Status
published
Products (3)
ibm/security_access_manager_for_web_8.0_firmware
8.0.0.2
ibm/security_access_manager_for_web_8.0_firmware
8.0.0.3
ibm/security_access_manager_for_web_appliance
8.0
Published
Jun 21, 2014
Tracked Since
Feb 18, 2026