Vulnerability Bulletins

IBM Security Bulletin: WebSphere Message Broker and IBM Integration Bus are affected by error handling vulnerability (CVE-2014-6170).

   
Affected software IBM
 
The HTTPInput node of WebSphere Message Broker and IBM Integration Bus can return a soap fault including sensitive information that can be used to conduct an attack on the system. CVE(s): CVE-2014-6170 Affected product(s) and affected version(s): IBM Integration Bus V9.0 WebSphere Message Broker V8.0 WebSphere Message Broker V7.0 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_websphere_message_broker_and_ibm_integration_bus_are_affected_by_error_handling_vulnerability_cve_2014_6170?lang=en_us