2.1

CVE-2014-6160

IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Service Registry And Repository Version 8.5
   Google ≫ Chrome Version -
   Ibm ≫ Webseal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.444
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www-01.ibm.com/support/docview.wss?uid=swg1IV63498
http://www-01.ibm.com/support/docview.wss?uid=swg21693389
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/97709