Required CVE Record Information
Description
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- http://www-01.ibm.com/support/docview.wss?uid=swg21623316 x_transferred
- www-01.ibm.com: IC89803 vendor-advisoryx_transferred
- exchange.xforce.ibmcloud.com: wmb-msg-auth-bypass(80666) vdb-entryx_transferred