IBM WebSphere DataPower XC10 Appliance Multiple Vulnerabilities
Last Update Date:
23 Nov 2012 11:06
Release Date:
23 Nov 2012
4776
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities have been identified in IBM WebSphere DataPower XC10 Appliance, which can be exploited by remote authenticated user can gain administrative privileges or cause denial of service conditions.
- A remote authenticated user can send specially crafted data to execute arbitrary JMX operations on the target system.
- A remote user can send specially crafted data to stop server processes.
- The product uses a common secret key for device-to-device communications. A remote user with knowledge of the key can impersonate appliance collective members.
Impact
- Elevation of Privilege
- Remote Code Execution
System / Technologies affected
- Versions V2.0.0.0 through V2.0.0.3
- Versions V2.1.0.0 through V2.1.0.2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply fixes
Vulnerability Identifier
Source
Related Link
Share with