PT-2012-6089 · Ibm · Ibm Websphere Datapower Xc10 Appliance
Publicado
2012-11-23
·
Atualizado
2017-08-29
·
CVE-2012-5759
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere DataPower XC10 Appliance versions 2.0.0.0 through 2.0.0.3
IBM WebSphere DataPower XC10 Appliance versions 2.1.0.0 through 2.1.0.2
Description
The issue allows remote authenticated users to bypass intended administrative-role requirements and perform arbitrary JMX operations.
Recommendations
For versions 2.0.0.0 through 2.0.0.3, update to a version outside of this range to mitigate the risk.
For versions 2.1.0.0 through 2.1.0.2, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting JMX operations to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Websphere Datapower Xc10 Appliance