Back to search
CVE-2014-6176
Published: Dec 16, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www-01.ibm.com/support/docview.wss?uid=swg21690780
x_refsource_CONFIRM
1031383
vdb-entry
x_refsource_SECTRACK
1031382
vdb-entry
x_refsource_SECTRACK
JR51593
vendor-advisory
x_refsource_AIXAPAR
ibm-websphere-cve20146176-weak-security(98488)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now