Access Control Flaw in IBM WebSphere Service Registry and Repository
CVE-2014-6177

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
24 December 2014

Summary

The IBM WebSphere Service Registry and Repository has a flaw that fails to enforce access controls during depth-0 retrieve operations. Consequently, this oversight allows remote authenticated users to access sensitive information without proper authorization, potentially leading to data breaches or unauthorized disclosure of sensitive information. Users of affected versions should consider applying the latest security updates to mitigate the risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.