Session Management Flaw in IBM WebSphere Service Registry and Repository
CVE-2014-6160
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 29 December 2014
Summary
IBM WebSphere Service Registry and Repository (WSRR) version 8.5 prior to 8.5.0.1 contains a session management flaw. When using Chrome and WebSEAL, the application does not correctly handle logout actions from the ServiceRegistryDashboard. This vulnerability can be exploited by remote attackers to bypass intended access restrictions by exploiting an unattended workstation, potentially granting unauthorized access to sensitive information.
References
Timeline
Vulnerability published
Vulnerability Reserved