Vulnerability Details CVE-2014-6170
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.2%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2014-6170
-
cpe:2.3:a:ibm:integration_bus:9.0
-
cpe:2.3:a:ibm:integration_bus:9.0.0.1
-
cpe:2.3:a:ibm:integration_bus:9.0.0.2
-
cpe:2.3:a:ibm:integration_bus:9.0.0.3
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.0.1
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.0.2
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.0.3
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.0.4
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.0.5
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.0.6
-
cpe:2.3:a:ibm:websphere_message_broker:7.0.0.7
-
cpe:2.3:a:ibm:websphere_message_broker:8.0
-
cpe:2.3:a:ibm:websphere_message_broker:8.0.0.1
-
cpe:2.3:a:ibm:websphere_message_broker:8.0.0.2
-
cpe:2.3:a:ibm:websphere_message_broker:8.0.0.3
-
cpe:2.3:a:ibm:websphere_message_broker:8.0.0.4
-
cpe:2.3:a:ibm:websphere_message_broker:8.0.0.5