CVE Database
/

CVE-2014-6176

Back to search

CVE-2014-6176

Published: Dec 16, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.

VendorProductVersions

n/a

n/a

affected
n/a

References

1031383
vdb-entry
x_refsource_SECTRACK
1031382
vdb-entry
x_refsource_SECTRACK
JR51593
vendor-advisory
x_refsource_AIXAPAR

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now