CVE-2014-3070

IBM WebSphere Application Server Unauthenticated Access Restriction Bypass via addFileRegistryAccount

Title source: llm
STIX 2.1

Description

The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/93777
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69296
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21681249
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI16765

Scores

EPSS 0.0214
EPSS Percentile 80.2%

Details

CWE
CWE-264
Status published
Products (16)
ibm/websphere_application_server 8.5.0.0
ibm/websphere_application_server 8.5.0.1
ibm/websphere_application_server 8.5.0.2
ibm/websphere_application_server 8.5.5.0
ibm/websphere_application_server 8.5.5.1
ibm/websphere_application_server 8.5.5.2
ibm/websphere_application_server 8.0.0.0
ibm/websphere_application_server 8.0.0.1
ibm/websphere_application_server 8.0.0.2
ibm/websphere_application_server 8.0.0.3
... and 6 more
Published Aug 22, 2014
Tracked Since Feb 18, 2026