Remote Spoofing Vulnerability in IBM WebSphere DataPower XC10 Appliance
CVE-2012-5756
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 23 November 2012
What is CVE-2012-5756?
The IBM WebSphere DataPower XC10 Appliance versions 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 contain a vulnerability that allows remote attackers to impersonate a container server. This occurs due to the use of a single shared secret key across multiple customers' installations when a collective configuration is enabled. Attackers could exploit this by either intercepting the key through network sniffing or utilizing their knowledge of the key from another installation, leading to unauthorized access and potential data breaches.