CVE-2014-3070
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0042 (0.4%)
Percentile: 61.9%
EPSS: 2026-05-06
Affects
ibm:websphere_application_serverTechnical description
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Published: 8/22/2014, 1:55:08 AM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI16765
- http://www-01.ibm.com/support/docview.wss?uid=swg21681249
- http://www.securityfocus.com/bid/69296
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93777
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI16765
- http://www-01.ibm.com/support/docview.wss?uid=swg21681249
- http://www.securityfocus.com/bid/69296
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93777