First published: Wed Dec 22 2010(Updated: )
IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Service Registry and Repository | =7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2644 is considered a medium severity vulnerability as it allows remote attackers to perform unauthorized governance actions.
To fix CVE-2010-2644, apply IBM's fix pack FP1 for the WebSphere Service Registry and Repository version 7.0.0.
CVE-2010-2644 can be exploited by remote attackers to make unauthorized API requests to the EJB interface.
CVE-2010-2644 affects IBM WebSphere Service Registry and Repository version 7.0.0 before fix pack FP1.
CVE-2010-2644 is a remote vulnerability, allowing attackers to exploit it without local access.