CVE-2014-6089

IBM Security Access Manager for Web 7.x < 7.0.0 FP10 and 8.x < 8.0.1 - Authenticated Denial of Service via File Upload

Title source: llm
STIX 2.1

Description

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (disrupted system operations) by uploading a file to a protected area.

References (4)

Core 4
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21684475
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV67358
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV67581
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95860

Scores

EPSS 0.0125
EPSS Percentile 66.4%

Details

CWE
CWE-19
Status published
Products (3)
ibm/security_access_manager_for_mobile 8.0
ibm/security_access_manager_for_web 7.0
ibm/security_access_manager_for_web 8.0
Published Dec 18, 2014
Tracked Since Feb 18, 2026