Authentication Bypass Vulnerability in IBM WebSphere Message Broker
CVE-2012-5952
Currently unrated
Summary
IBM WebSphere Message Broker versions 6.1 prior to 6.1.0.12, 7.0 prior to 7.0.0.6, and 8.0 prior to 8.0.0.2 lack proper validation of Basic Authentication credentials. This flaw allows remote attackers to execute WS-Addressing and WS-Security operations without appropriate authentication, potentially leading to the transmission of unauthenticated messages through various attack vectors. Proper security measures and upgrades are essential to mitigate this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved