CVE-2014-6176

IBM Business Process Manager SSLv3 Downgrade in SCA HTTP Import Binding

Title source: llm
STIX 2.1

Description

IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21690780
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031383
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031382
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR51593
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98488

Scores

EPSS 0.0182
EPSS Percentile 76.5%

Details

CWE
CWE-310
Status published
Products (14)
ibm/business_process_manager 7.5.0.0
ibm/business_process_manager 7.5.0.1
ibm/business_process_manager 7.5.1.0
ibm/business_process_manager 7.5.1.1
ibm/business_process_manager 8.0.0.0
ibm/business_process_manager 8.0.1.0
ibm/business_process_manager 8.0.1.1
ibm/business_process_manager 8.0.1.2
ibm/business_process_manager 8.0.1.3
ibm/business_process_manager 8.5.0.0
... and 4 more
Published Dec 16, 2014
Tracked Since Feb 18, 2026