VendorsIBMintegration_bus9.0.0.5
Vulnerabilities

IBM Integration Bus 9.0.0.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2017-1694
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
Published 2017-12-20 · Modified
8.1EPSS 0.008
CVE-2017-1693
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164.
Published 2018-01-19 · Modified
6.8EPSS 0.009
CVE-2017-1207
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.
Published 2017-07-05 · Modified
5.5EPSS 0.003
CVE-2016-2961
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.
Published 2016-07-02 · Modified
5.3EPSS 0.015
CVE-2017-1126
IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.
Published 2017-10-03 · Modified
5.3EPSS 0.012
CVE-2017-1144
IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033.
Published 2017-07-05 · Modified
2.5EPSS 0.003