First published: Mon Dec 29 2014(Updated: )
IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Service Registry and Repository | =8.5 | |
Google Chrome | ||
Ibm Webseal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6160 is considered a medium severity vulnerability due to its potential for unauthorized access.
To mitigate CVE-2014-6160, upgrading IBM WebSphere Service Registry and Repository to version 8.5.0.1 or later is recommended.
CVE-2014-6160 allows remote attackers to bypass access restrictions on unattended workstations, potentially exposing sensitive data.
IBM WebSphere Service Registry and Repository versions prior to 8.5.0.1 are affected by CVE-2014-6160.
While specific exploits for CVE-2014-6160 have not been widely reported, the vulnerability's nature makes it a potential target for attackers.