Skip to main content

IBM WebSphere DataPower XC10 Appliance Multiple Vulnerabilities

Last Update Date: 23 Nov 2012 11:06 Release Date: 23 Nov 2012 4776 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in IBM WebSphere DataPower XC10 Appliance, which can be exploited by remote authenticated user can gain administrative privileges or cause denial of service conditions.

  1. A remote authenticated user can send specially crafted data to execute arbitrary JMX operations on the target system.
  2. A remote user can send specially crafted data to stop server processes.
  3. The product uses a common secret key for device-to-device communications. A remote user with knowledge of the key can impersonate appliance collective members.

Impact

  • Elevation of Privilege
  • Remote Code Execution

System / Technologies affected

  • Versions V2.0.0.0 through V2.0.0.3
  • Versions V2.1.0.0 through V2.1.0.2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Apply fixes

Vulnerability Identifier


Source


Related Link