IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring.
2014-04-15T23:13:17.117
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:N/AC:H/Au:S/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | messagesight_jms_client | 1.0.0.0 | Yes |
Application | ibm | messagesight_jms_client | 1.0.0.1 | Yes |
Application | ibm | messagesight_jms_client | 1.1.0.0 | Yes |
Hardware | ibm | messagesight | - | Yes |