Authentication Bypass Vulnerability in IBM WebSphere Message Broker
CVE-2012-5952

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 February 2013

Summary

IBM WebSphere Message Broker versions 6.1 prior to 6.1.0.12, 7.0 prior to 7.0.0.6, and 8.0 prior to 8.0.0.2 lack proper validation of Basic Authentication credentials. This flaw allows remote attackers to execute WS-Addressing and WS-Security operations without appropriate authentication, potentially leading to the transmission of unauthenticated messages through various attack vectors. Proper security measures and upgrades are essential to mitigate this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.