CVE-2014-6155
Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files…
Does this matter?
Lower severity and a low EPSS score (2.42%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files via unspecified vectors.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 2.42% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ibm/websphere service registry and repository
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/61805
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV63585
- http://www.ibm.com/support/docview.wss?uid=swg21693384Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21693387Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21693389Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97678
- http://secunia.com/advisories/61805
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV63585
- http://www.ibm.com/support/docview.wss?uid=swg21693384Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21693387Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21693389Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97678
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.