CVE-2014-3070
IBM WebSphere Application Server Unauthenticated Access Restriction Bypass via addFileRegistryAccount
Title source: llmDescription
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/93777
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/69296
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21681249
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI16765
Scores
EPSS
0.0214
EPSS Percentile
80.2%
Details
CWE
CWE-264
Status
published
Products (16)
ibm/websphere_application_server
8.5.0.0
ibm/websphere_application_server
8.5.0.1
ibm/websphere_application_server
8.5.0.2
ibm/websphere_application_server
8.5.5.0
ibm/websphere_application_server
8.5.5.1
ibm/websphere_application_server
8.5.5.2
ibm/websphere_application_server
8.0.0.0
ibm/websphere_application_server
8.0.0.1
ibm/websphere_application_server
8.0.0.2
ibm/websphere_application_server
8.0.0.3
... and 6 more
Published
Aug 22, 2014
Tracked Since
Feb 18, 2026