| Vulnerability Name: | CVE-2014-0927 (CCN-92259) | ||||||||||||
| Assigned: | 2014-06-02 | ||||||||||||
| Published: | 2014-06-02 | ||||||||||||
| Updated: | 2018-05-22 | ||||||||||||
| Summary: | The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259. | ||||||||||||
| CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-287 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-0927 Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21674739 Source: CCN Type: IBM Security Bulletin 1674739 Vulnerabilities found in IBM Sterling B2B Integrator and IBM Sterling File Gateway ( CVE-2014-0114, CVE-2014-0927, CVE-2014-0912) Source: XF Type: UNKNOWN ibm-sterling-cve20140927-sec-bypass(92259) Source: XF Type: VDB Entry, Vendor Advisory ibm-sterling-cve20140927-sec-bypass(92259) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||