Access Control Flaw in IBM WebSphere Service Registry and Repository
CVE-2014-6177
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 24 December 2014
Summary
The IBM WebSphere Service Registry and Repository has a flaw that fails to enforce access controls during depth-0 retrieve operations. Consequently, this oversight allows remote authenticated users to access sensitive information without proper authorization, potentially leading to data breaches or unauthorized disclosure of sensitive information. Users of affected versions should consider applying the latest security updates to mitigate the risk.
References
Timeline
Vulnerability published
Vulnerability Reserved