First published: Thu Dec 11 2014(Updated: )
The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Datapower Xc10 Appliance Firmware | =2.1.0.0 | |
Ibm Websphere Datapower Xc10 Appliance Firmware | =2.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6143 is classified as a medium severity vulnerability.
To fix CVE-2014-6143, upgrade the IBM WebSphere DataPower XC10 appliance to version 2.1.0.0 FP4 or higher.
Organizations using IBM WebSphere DataPower XC10 appliance firmware versions 2.1.0.0 and 2.5.0.0 prior to FP4 are affected by CVE-2014-6143.
CVE-2014-6143 is a local information disclosure vulnerability.
An attacker with local access can obtain sensitive information by exploiting CVE-2014-6143.