IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.3 does not perform access-control checks for depth-0 retrieve operations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 02:13
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV24386 - | |
| References | () http://www.ibm.com/support/docview.wss?uid=swg21693381 - Vendor Advisory | |
| References | () http://www.ibm.com/support/docview.wss?uid=swg21693384 - Vendor Advisory | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/98492 - | 
Information
                Published : 2014-12-24 11:59
Updated : 2025-04-12 10:46
NVD link : CVE-2014-6177
Mitre link : CVE-2014-6177
CVE.ORG link : CVE-2014-6177
JSON object : View
Products Affected
                ibm
- websphere_service_registry_and_repository
 
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
