First published: Sun Aug 23 2015(Updated: )
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Integration Bus | =9.0 | |
IBM Integration Bus | =10.0 | |
IBM WebSphere Message Broker | =7.0. | |
IBM WebSphere Message Broker | =7.0.0.1 | |
IBM WebSphere Message Broker | =7.0.0.2 | |
IBM WebSphere Message Broker | =7.0.0.3 | |
IBM WebSphere Message Broker | =7.0.0.4 | |
IBM WebSphere Message Broker | =7.0.0.5 | |
IBM WebSphere Message Broker | =7.0.0.6 | |
IBM WebSphere Message Broker | =7.0.0.7 | |
IBM WebSphere Message Broker | =8.0 | |
IBM WebSphere Message Broker | =8.0.0.1 | |
IBM WebSphere Message Broker | =8.0.0.2 | |
IBM WebSphere Message Broker | =8.0.0.3 | |
IBM WebSphere Message Broker | =8.0.0.4 | |
IBM WebSphere Message Broker | =8.0.0.5 | |
IBM WebSphere Message Broker | =8.0.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-2018 is classified as moderate due to the potential exposure of sensitive information to remote authenticated users.
To mitigate CVE-2015-2018, upgrade IBM Integration Bus to version 10.0.0.1 or above and WebSphere Message Broker to versions 7.0.0.8 or 8.0.0.7 or later.
CVE-2015-2018 affects IBM Integration Bus versions 9.0 and 10.0, as well as WebSphere Message Broker versions 7.0 to 8.0.
CVE-2015-2018 allows remote authenticated users to potentially obtain sensitive information from the affected systems.
There are no known workaround solutions for CVE-2015-2018, so applying the recommended updates is essential.