Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-682f-956r-w9gv

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."

EPSS

Процентиль: 62%
0.00433
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 17 лет назад

IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."

EPSS

Процентиль: 62%
0.00433
Низкий

Дефекты

CWE-287