CVE Vulnerabilities

CVE-2014-6176

Published: Dec 16, 2014 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.

Affected Software

Name Vendor Start Version End Version
Business_process_manager Ibm 8.5.5.0 8.5.5.0
Business_process_manager Ibm 8.5.0.1 8.5.0.1
Business_process_manager Ibm 8.0.1.3 8.0.1.3
Business_process_manager Ibm 7.5.0.0 7.5.0.0
Business_process_manager Ibm 7.5.1.0 7.5.1.0
Business_process_manager Ibm 7.5.0.1 7.5.0.1
Business_process_manager Ibm 7.5.1.1 7.5.1.1
Business_process_manager Ibm 8.0.0.0 8.0.0.0
Business_process_manager Ibm 8.0.1.2 8.0.1.2
Business_process_manager Ibm 8.5.0.0 8.5.0.0
Business_process_manager Ibm 8.0.1.1 8.0.1.1
Business_process_manager Ibm 8.0.1.0 8.0.1.0

References