Improper Handling of jct-nist-compliance Parameter in IBM Security Access Manager for Web
CVE-2014-3052
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 21 June 2014
Summary
The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0, specifically in firmware versions 8.0.0.2 and 8.0.0.3, misinterprets the jct-nist-compliance parameter. This flaw could allow remote attackers to exploit weak SSL encryption configurations that do not comply with NIST SP 800-131A guidelines, leading to potential exposure of sensitive information.
References
Timeline
Vulnerability published
Vulnerability Reserved