Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fh54-rxv3-35p2

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 13 лет назад

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-287