CVE-2014-3060
Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- ibm/websphere datapower xc10 appliance firmware · ibm/websphere datapower xc10 appliance
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT03476Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685705Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93534
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT03476Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685705Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93534
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.