VulnerabilityModified
CVE-2014-6170
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
MEDIUM 5.0EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/integration bus · ibm/websphere message broker
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929
- http://www-01.ibm.com/support/docview.wss?uid=swg21690725Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98309
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929
- http://www-01.ibm.com/support/docview.wss?uid=swg21690725Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98309
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.