CVE-2014-6160 Information

Description

IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1 when Chrome and WebSEAL are used does not properly process ServiceRegistryDashboard logout actions which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg1IV63498 http://www-01.ibm.com/support/docview.wss?uid=swg21693389 https://exchange.xforce.ibmcloud.com/vulnerabilities/97709

Share on: