CVE-2010-2644
IBM WebSphere Service Registry and Repository <7.0.0 - Info Disclosure
Title source: llmDescription
IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg24026132
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/63640
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42742
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ72563
Scores
EPSS
0.0121
EPSS Percentile
65.2%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/websphere_service_registry_and_repository
7.0.0
Published
Dec 22, 2010
Tracked Since
Feb 18, 2026