Improper Handling of jct-nist-compliance Parameter in IBM Security Access Manager for Web
CVE-2014-3052

Currently unrated

Key Information:

Summary

The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0, specifically in firmware versions 8.0.0.2 and 8.0.0.3, misinterprets the jct-nist-compliance parameter. This flaw could allow remote attackers to exploit weak SSL encryption configurations that do not comply with NIST SP 800-131A guidelines, leading to potential exposure of sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.