IBM WebSphere DataPower SOA Appliances XML Encryption Information Disclosure Vulnerability
BID:55786
Info
IBM WebSphere DataPower SOA Appliances XML Encryption Information Disclosure Vulnerability
| Bugtraq ID: | 55786 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2011 12:00AM |
| Updated: | Jun 29 2011 12:00AM |
| Credit: | Juraj Somorovsky of Ruhr-University Bochum |
| Vulnerable: |
IBM WebSphere DataPower SOA Appliance Firmware 3.8.2 IBM WebSphere DataPower SOA Appliance Firmware 3.8.1 IBM WebSphere DataPower SOA Appliance Firmware 3.8 .1 IBM WebSphere DataPower SOA Appliance Firmware 3.7.3 .7 IBM WebSphere DataPower SOA Appliance Firmware 3.7.3 IBM WebSphere DataPower SOA Appliance Firmware 3.7.2 .8 IBM WebSphere DataPower SOA Appliance Firmware 3.7.2 IBM WebSphere DataPower SOA Appliance Firmware 3.7.1 .12 IBM WebSphere DataPower SOA Appliance Firmware 3.7.1 IBM WebSphere DataPower SOA Appliance Firmware 4.0 IBM WebSphere DataPower SOA Appliance Firmware 3.8 |
| Not Vulnerable: |
IBM WebSphere DataPower SOA Appliance Firmware 4.0.1 0 IBM WebSphere DataPower SOA Appliance Firmware 3.8.2 4 IBM WebSphere DataPower SOA Appliance Firmware 3.8.1 12 IBM WebSphere DataPower SOA Appliance Firmware 3.8 13 IBM WebSphere DataPower SOA Appliance Firmware 3.7.3 19 |
Discussion
IBM WebSphere DataPower SOA Appliances XML Encryption Information Disclosure Vulnerability
IBM WebSphere DataPower SOA Appliances are prone to an information disclosure vulnerability due to a design error in the W3C XML Encryption Standard when using the cipher-block chaining (CBC) mode of operation.
Successful exploits may allow an attacker to gain access to sensitive information that may aid in further attacks.
IBM WebSphere DataPower SOA Appliances are prone to an information disclosure vulnerability due to a design error in the W3C XML Encryption Standard when using the cipher-block chaining (CBC) mode of operation.
Successful exploits may allow an attacker to gain access to sensitive information that may aid in further attacks.
Exploit / POC
IBM WebSphere DataPower SOA Appliances XML Encryption Information Disclosure Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
IBM WebSphere DataPower SOA Appliances XML Encryption Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM WebSphere DataPower SOA Appliances XML Encryption Information Disclosure Vulnerability
References:
References: