CVE-2014-6110

IBM Security Identity Manager 6.x < 6.0.0.3 IF14 - Unauthenticated Session Access via Improper Logout

Title source: llm
STIX 2.1

Description

IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.

References (8)

Core 8
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66642
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21689779
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/96179
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66645

Scores

EPSS 0.0058
EPSS Percentile 43.3%

Details

CWE
CWE-284
Status published
Products (4)
ibm/security_identity_manager 6.0.0.0
ibm/security_identity_manager 6.0.0.1
ibm/security_identity_manager 6.0.0.2
ibm/security_identity_manager 6.0.0.3
Published Nov 18, 2014
Tracked Since Feb 18, 2026