CVE-2014-6160

IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:websphere_service_registry_and_repository:8.5:*:*:*:*:*:*:*
OR cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webseal:-:*:*:*:*:*:*:*

Information

Published : 2014-12-28 18:59

Updated : 2017-09-07 18:29


NVD link : CVE-2014-6160

Mitre link : CVE-2014-6160


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

ibm

  • websphere_service_registry_and_repository
  • webseal

google

  • chrome