Required CVE Record Information
Description
IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.3 does not perform access-control checks for depth-0 retrieve operations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- http://www.ibm.com/support/docview.wss?uid=swg21693384 x_transferred
- www-01.ibm.com: IV24386 vendor-advisoryx_transferred
- http://www.ibm.com/support/docview.wss?uid=swg21693381 x_transferred
- exchange.xforce.ibmcloud.com: ibm-wsrr-cve20146177-sec-bypass(98492) vdb-entryx_transferred