CVE-2014-6153: Medium severity ibm websphere service registry and repository vulnerability

Published Dec 24, 2014
·
Updated

The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Affected Software

21 affected components
IBM WebSphere Service Registry and Repository=6.3.0
IBM WebSphere Service Registry and Repository=6.3.0.1
IBM WebSphere Service Registry and Repository=6.3.0.2
IBM WebSphere Service Registry and Repository=6.3.0.3
IBM WebSphere Service Registry and Repository=6.3.0.4
IBM WebSphere Service Registry and Repository=6.3.0.5
IBM WebSphere Service Registry and Repository=7.0.0
IBM WebSphere Service Registry and Repository=7.0.0.1
IBM WebSphere Service Registry and Repository=7.0.0.2
IBM WebSphere Service Registry and Repository=7.0.0.3
IBM WebSphere Service Registry and Repository=7.0.0.4
IBM WebSphere Service Registry and Repository=7.0.0.5
IBM WebSphere Service Registry and Repository=7.5.0.0
IBM WebSphere Service Registry and Repository=7.5.0.1
IBM WebSphere Service Registry and Repository=7.5.0.2
IBM WebSphere Service Registry and Repository=7.5.0.3
IBM WebSphere Service Registry and Repository=7.5.0.4
IBM WebSphere Service Registry and Repository=8.0
IBM WebSphere Service Registry and Repository=8.0.0.1
IBM WebSphere Service Registry and Repository=8.0.0.2
IBM WebSphere Service Registry and Repository=8.5

Event History

Dec 24, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2014-6153?

CVE-2014-6153 is classified as a medium-severity vulnerability due to its potential for remote exploitation.

2

How do I fix CVE-2014-6153?

To fix CVE-2014-6153, ensure that the secure flag is set for cookies in your IBM WebSphere Service Registry and Repository configuration.

3

Which versions are affected by CVE-2014-6153?

CVE-2014-6153 affects IBM WebSphere Service Registry and Repository versions 6.3.x to 6.3.0.5, 7.0.x to 7.0.0.5, 7.5.x to 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1.

4

What kind of attack can CVE-2014-6153 enable?

CVE-2014-6153 can enable remote attackers to capture session cookies, potentially compromising user sessions.

5

Is there a patch available for CVE-2014-6153?

Yes, IBM has released patches for affected versions of the WebSphere Service Registry and Repository to mitigate CVE-2014-6153.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203