The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
2015-02-02T01:59:02.593
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | integration_bus | 9.0 | Yes |
Application | ibm | integration_bus | 9.0.0.1 | Yes |
Application | ibm | integration_bus | 9.0.0.2 | Yes |
Application | ibm | integration_bus | 9.0.0.3 | Yes |
Application | ibm | websphere_message_broker | 7.0. | Yes |
Application | ibm | websphere_message_broker | 7.0.0.1 | Yes |
Application | ibm | websphere_message_broker | 7.0.0.2 | Yes |
Application | ibm | websphere_message_broker | 7.0.0.3 | Yes |
Application | ibm | websphere_message_broker | 7.0.0.4 | Yes |
Application | ibm | websphere_message_broker | 7.0.0.5 | Yes |
Application | ibm | websphere_message_broker | 7.0.0.6 | Yes |
Application | ibm | websphere_message_broker | 7.0.0.7 | Yes |
Application | ibm | websphere_message_broker | 8.0 | Yes |
Application | ibm | websphere_message_broker | 8.0.0.1 | Yes |
Application | ibm | websphere_message_broker | 8.0.0.2 | Yes |
Application | ibm | websphere_message_broker | 8.0.0.3 | Yes |
Application | ibm | websphere_message_broker | 8.0.0.4 | Yes |
Application | ibm | websphere_message_broker | 8.0.0.5 | Yes |