PT-2015-3826 · Ibm · Ibm Websphere Message Broker+1

Published

2015-02-02

·

Updated

2017-09-08

·

CVE-2014-6170

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Message Broker versions 7.0 through 7.0.0.7 IBM WebSphere Message Broker version 8.0 through 8.0.0.5 IBM Integration Bus versions 9.0 through 9.0.0.3
Description The issue allows remote attackers to obtain sensitive information by triggering a SOAP fault, specifically affecting the HTTPInput node.
Recommendations For IBM WebSphere Message Broker versions 7.0 through 7.0.0.7, update to version 7.0.0.8 or later. For IBM WebSphere Message Broker version 8.0 through 8.0.0.5, update to version 8.0.0.6 or later. For IBM Integration Bus versions 9.0 through 9.0.0.3, update to version 9.0.0.4 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-6170

Affected Products

Ibm Integration Bus
Ibm Websphere Message Broker