First published: Wed Dec 24 2014(Updated: )
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Service Registry and Repository | =6.3.0 | |
IBM WebSphere Service Registry and Repository | =6.3.0.1 | |
IBM WebSphere Service Registry and Repository | =6.3.0.2 | |
IBM WebSphere Service Registry and Repository | =6.3.0.3 | |
IBM WebSphere Service Registry and Repository | =6.3.0.4 | |
IBM WebSphere Service Registry and Repository | =6.3.0.5 | |
IBM WebSphere Service Registry and Repository | =7.0.0 | |
IBM WebSphere Service Registry and Repository | =7.0.0.1 | |
IBM WebSphere Service Registry and Repository | =7.0.0.2 | |
IBM WebSphere Service Registry and Repository | =7.0.0.3 | |
IBM WebSphere Service Registry and Repository | =7.0.0.4 | |
IBM WebSphere Service Registry and Repository | =7.0.0.5 | |
IBM WebSphere Service Registry and Repository | =7.5.0.0 | |
IBM WebSphere Service Registry and Repository | =7.5.0.1 | |
IBM WebSphere Service Registry and Repository | =7.5.0.2 | |
IBM WebSphere Service Registry and Repository | =7.5.0.3 | |
IBM WebSphere Service Registry and Repository | =7.5.0.4 | |
IBM WebSphere Service Registry and Repository | =8.0 | |
IBM WebSphere Service Registry and Repository | =8.0.0.1 | |
IBM WebSphere Service Registry and Repository | =8.0.0.2 | |
IBM WebSphere Service Registry and Repository | =8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6153 is classified as a medium-severity vulnerability due to its potential for remote exploitation.
To fix CVE-2014-6153, ensure that the secure flag is set for cookies in your IBM WebSphere Service Registry and Repository configuration.
CVE-2014-6153 affects IBM WebSphere Service Registry and Repository versions 6.3.x to 6.3.0.5, 7.0.x to 7.0.0.5, 7.5.x to 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1.
CVE-2014-6153 can enable remote attackers to capture session cookies, potentially compromising user sessions.
Yes, IBM has released patches for affected versions of the WebSphere Service Registry and Repository to mitigate CVE-2014-6153.