CVE-2014-3053

IBM Security Access Manager For Web 8... - Authentication Bypass

Title source: rule

Description

The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.

Scores

EPSS 0.0072
EPSS Percentile 72.1%

Classification

CWE
CWE-287
Status draft

Affected Products (8)

ibm/security_access_manager_for_web_8.0_firmware
ibm/security_access_manager_for_web_8.0_firmware
ibm/security_access_manager_for_web_appliance
ibm/security_access_manager_for_mobile_software
ibm/security_access_manager_for_web_software
ibm/security_access_manager_for_web_software
ibm/security_access_manager_for_mobile_appliance
ibm/security_access_manager_for_web_appliance

Timeline

Published Jun 21, 2014
Tracked Since Feb 18, 2026