IBM WebSphere DataPower XC10 Denial of Service and Security Bypass Vulnerabilities
BID:56617
Info
IBM WebSphere DataPower XC10 Denial of Service and Security Bypass Vulnerabilities
| Bugtraq ID: | 56617 |
| Class: | Unknown |
| CVE: |
CVE-2012-5756 CVE-2012-5758 CVE-2012-5759 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2012 12:00AM |
| Updated: | Mar 12 2013 10:55PM |
| Credit: | Reported by the vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM WebSphere DataPower XC10 Denial of Service and Security Bypass Vulnerabilities
IBM WebSphere DataPower XC10 is prone to a denial-of-service vulnerability, a security-bypass weakness, and a security-bypass vulnerability.
Attackers can exploit these issues to perform denial-of-service attacks, bypass certain security restrictions, man-in-the-middle attacks, or impersonate trusted servers; this will aid in further attacks.
IBM WebSphere DataPower XC10 versions 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 are vulnerable.
IBM WebSphere DataPower XC10 is prone to a denial-of-service vulnerability, a security-bypass weakness, and a security-bypass vulnerability.
Attackers can exploit these issues to perform denial-of-service attacks, bypass certain security restrictions, man-in-the-middle attacks, or impersonate trusted servers; this will aid in further attacks.
IBM WebSphere DataPower XC10 versions 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 are vulnerable.