IBM Integration Bus 10.0.0.9

CPE Details

IBM Integration Bus 10.0.0.9
10.0.0.9
2017-10-13
11h14 +00:00
2017-10-13
11h14 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:integration_bus:10.0.0.9:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

integration_bus

Version

10.0.0.9

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-1801 2019-02-04 21h00 +00:00 IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.
5.3
Medium
CVE-2017-1418 2018-11-26 17h00 +00:00 IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.
5.5
Medium
CVE-2017-1693 2018-01-19 14h00 +00:00 IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164.
5.6
Medium
CVE-2017-1694 2017-12-20 18h00 +00:00 IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
8.1
High
CVE-2017-1126 2017-10-03 17h00 +00:00 IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.
5.3
Medium