PT-2014-5046 · Ibm · Ibm Security Access Manager For Web
Published
2014-06-21
·
Updated
2017-08-29
·
CVE-2014-3052
CVSS v2.0
3.3
Low
| Vector | AV:A/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Access Manager (ISAM) for Web versions 8.0.0.2 through 8.0.0.3
Description
The issue concerns the reverse-proxy feature in IBM Security Access Manager (ISAM) for Web, where the
jct-nist-compliance parameter is interpreted in the opposite manner of its intended purpose. This misinterpretation makes it easier for remote attackers to obtain sensitive information by exploiting weak SSL encryption settings that do not comply with NIST SP 800-131A.Recommendations
For versions 8.0.0.2 and 8.0.0.3, consider disabling the reverse-proxy feature until a patch is available to correct the interpretation of the
jct-nist-compliance parameter. Restrict access to sensitive information by leveraging strong SSL encryption settings that comply with NIST SP 800-131A to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Access Manager For Web