CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2014-6177 IBM WebSphere Service Registry and Repository Multiple Vulnerabilities漏洞银行丨0DAY BANK

2016年8月12日 2470点热度 0人点赞 0条评论

漏洞信息

IBM WebSphere Service Registry and Repository is a Lifecycle management application to track lifecycle, versions and availability of services. Multiple security issues have been found in IBM WebSphere Service Registry and Repository application which allow attackers to retrieve sensitive information:
CVE-2014-6177:IBM WebSphere Service Registry and Repository (WSRR) fails to perform access-control checks for depth-0 retrieve operations, allowing remote authenticated users obtain sensitive information via unspecified vectors.
CVE-2014-6181:IBM WebSphere Service Registry and Repository (WSRR) fails to perform access-control checks for contained objects,allowing remote authenticated users obtain sensitive information via unspecified vectors.
CVE-2014-6186:IBM WebSphere Service Registry and Repository (WSRR) allows remote authenticated users to bypass intended object-access restrictions via the datagraph
Affected Versions:
IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5
IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5
IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.3
IBM WebSphere Service Registry and Repository (WSRR) 8.0.x before 8.0.0.1

漏洞危害

An authenticated remote attacker may exploit these vulnerabilities to bypass access restrictions and obtain sensitive information.

解决方案

Customers are advised to install the patch provided by IBM.Further more information can be obtained from IBM

Patch:
Following are links for downloading patches to fix the vulnerabilities:

IBM: Windows

www.0daybank.org

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me