CVE-2014-6176
IBM Business Process Manager SSLv3 Downgrade in SCA HTTP Import Binding
Title source: llmDescription
IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21690780
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031383
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031382
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR51593
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98488
Scores
EPSS
0.0182
EPSS Percentile
76.5%
Details
CWE
CWE-310
Status
published
Products (14)
ibm/business_process_manager
7.5.0.0
ibm/business_process_manager
7.5.0.1
ibm/business_process_manager
7.5.1.0
ibm/business_process_manager
7.5.1.1
ibm/business_process_manager
8.0.0.0
ibm/business_process_manager
8.0.1.0
ibm/business_process_manager
8.0.1.1
ibm/business_process_manager
8.0.1.2
ibm/business_process_manager
8.0.1.3
ibm/business_process_manager
8.5.0.0
... and 4 more
Published
Dec 16, 2014
Tracked Since
Feb 18, 2026