CVE-2014-3051

The Internet Service Monitor (ISM) agent in IBM Tivoli Composite Application Manager (ITCAM) for Transactions 7.1 and 7.2 before 7.2.0.3 IF28, 7.3 before 7.3.0.1 IF30, and 7.4 before 7.4.0.0 IF18 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain credential information via a crafted certificate.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_composite_application_manager_for_transactions:7.3.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:07

Type Values Removed Values Added
References () http://secunia.com/advisories/59756 - () http://secunia.com/advisories/59756 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg21682290 - Patch, Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21682290 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/93444 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/93444 -

Information

Published : 2014-10-29 10:55

Updated : 2024-11-21 02:07


NVD link : CVE-2014-3051

Mitre link : CVE-2014-3051

CVE.ORG link : CVE-2014-3051


JSON object : View

Products Affected

ibm

  • tivoli_composite_application_manager_for_transactions
CWE
CWE-310

Cryptographic Issues