← Vulnerability feed

Vulnerability record · CVE-2014-0963 · published 8 May 2014

CVE-2014-0963: Ibm security access manager for web software vulnerability

Ibm · Security Access Manager For Web Software

The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.

7.1 CVSS 2.0 High EPSS 3.1% · top 12.8% CWE-399 · CWE-399
7.1CVSS 2.0 base score
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
24References
17 Jun 2026Last modified by NVD

Description

The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.

AV:N/AC:M/Au:N/C:N/I:N/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0963 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-4823Ibm security access manager for web 7.0 firmware os command injection vulnerabilityThe administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security A…EPSS 2.8%10.0CVE-2014-3073Ibm security access manager for mobile software vulnerabilityUnspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote atta…EPSS 4.2%8.0CVE-2014-3053Ibm security access manager for web 8.0 firmware improper authentication vulnerabilityThe Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Acce…EPSS 1.4%7.1CVE-2014-4809Ibm security access manager for web 8.0 firmware vulnerabilityThe WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, when e-community SS…EPSS 1.5%6.1CVE-2017-1489Ibm tivoli access manager for e-business open redirect vulnerabilityIBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authenticatio…EPSS 1.2%4.3CVE-2014-6079Ibm security access manager for mobile 8.0 firmware cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and…EPSS 1.4%3.3CVE-2014-3052Ibm security access manager for web 8.0 firmware vulnerabilityThe reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance para…EPSS 0.36%8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2014-0963), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.