The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/98309 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21690725 | vendor advisory |