CVE-2014-0924: IBM Messagesight

Medium severity, CVSS 4.6. EPSS: 1.1% chance of exploitation in the next 30 days.

IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring.

Affected products

  • IBM Messagesight
  • IBM Messagesight Jms Client: version 1.0.0.0 only; version 1.0.0.1 only; version 1.1.0.0 only

Published 2014-04-15. Last modified 2026-06-17.