In certain configurations, a security vulnerability exists in WebSphere DataPower XC10 Appliance. A WebSphere eXtreme Scale attacker could gain administrative access to the device.
VULNERABILITY DETAILS:
CVEID:CVE-2014-3059
In certain configurations, a security vulnerability in the WebSphere DataPower XC10 Appliance exists where XC10 Administrative Console could allow a malicious user to gain administrative access to the device .
CVSS Base Score: 1.9
_CVSS Temporal Score: See _https://exchange.xforce.ibmcloud.com/vulnerabilities/93533 for the current score
CVSS Environmental Score*: Undefined
_CVSS Vector: _****(AV:L/AC:M/Au:N/C:P/I:N/A:N)
CVEID:CVE-2014-3060
DESCRIPTION:
In certain configurations, a security vulnerability in the WebSphere DataPower XC10 Appliance exists where WebSphere DataPower XC10 Appliance could allow an attacker to gain administrative access to the device if the session cookie was captured .
CVSS Base Score: 1.9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/93534 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N)
WebSphere DataPower XC10 Appliance Version 2.5
Product
| VRMF |APARs|Link to Interim Fix or Fix Pack
—|—|—|—
WebSphere DataPower XC10 Appliance for appliance 7199-92X | Version 2.5.0 | IT03476 | http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+DataPower+XC10+Appliance&release=2.5.0.3&platform=All&function=all
WebSphere DataPower XC10 Virtual Image | Version 2.5.0 | IT03476 | http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+DataPower+XC10+Appliance&release=2.5.0.3&platform=All&function=all
None