IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure that HTTPS is used, which allows remote attackers to obtain sensitive information by sniffing the network during an HTTP session.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2014-12-18T16:00:00

Updated: 2024-08-06T12:03:02.350Z

Reserved: 2014-09-02T00:00:00

Link: CVE-2014-6086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2014-12-18T16:59:07.473

Modified: 2017-09-08T01:29:07.997

Link: CVE-2014-6086

cve-icon Redhat

No data.