PT-2014-5046 · Ibm · Ibm Security Access Manager For Web
Publicado
2014-06-21
·
Atualizado
2017-08-29
·
CVE-2014-3052
CVSS v2.0
3.3
Baixa
| Vetor | AV:A/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Access Manager (ISAM) for Web versions 8.0.0.2 through 8.0.0.3
Description
The issue concerns the reverse-proxy feature in IBM Security Access Manager (ISAM) for Web, where the
jct-nist-compliance parameter is interpreted in the opposite manner of its intended purpose. This misinterpretation makes it easier for remote attackers to obtain sensitive information by exploiting weak SSL encryption settings that do not comply with NIST SP 800-131A.Recommendations
For versions 8.0.0.2 and 8.0.0.3, consider disabling the reverse-proxy feature until a patch is available to correct the interpretation of the
jct-nist-compliance parameter. Restrict access to sensitive information by leveraging strong SSL encryption settings that comply with NIST SP 800-131A to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Security Access Manager For Web