Session Management Flaw in IBM WebSphere Service Registry and Repository
CVE-2014-6160

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 December 2014

Summary

IBM WebSphere Service Registry and Repository (WSRR) version 8.5 prior to 8.5.0.1 contains a session management flaw. When using Chrome and WebSEAL, the application does not correctly handle logout actions from the ServiceRegistryDashboard. This vulnerability can be exploited by remote attackers to bypass intended access restrictions by exploiting an unattended workstation, potentially granting unauthorized access to sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.