Vulnerability Description
The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Access Manager For Web Software | 7.0 |
| Ibm | Security Access Manager For Web Appliance | 7.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/58845
- http://secunia.com/advisories/59245
- http://secunia.com/advisories/59249
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV59660
- http://www-01.ibm.com/support/docview.wss?uid=swg21672192Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676091PatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092PatchVendor Advisory
- http://www-304.ibm.com/support/docview.wss?uid=swg21680803
- http://www.ibm.com/support/docview.wss?uid=swg21675496
- http://www.securityfocus.com/bid/67238
- http://www.securitytracker.com/id/1030707
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92844
- http://secunia.com/advisories/58845
- http://secunia.com/advisories/59245
- http://secunia.com/advisories/59249
FAQ
What is CVE-2014-0963?
CVE-2014-0963 is a vulnerability with a CVSS score of 7.1 (HIGH). The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attac...
How severe is CVE-2014-0963?
CVE-2014-0963 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0963?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Access Manager For Web Software, Ibm Security Access Manager For Web Appliance.