CVE-2014-6170
Estado: ModificadaMedia (5)—
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.35%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-200
Referencias
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929
- http://www-01.ibm.com/support/docview.wss?uid=swg21690725
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98309
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929
- http://www-01.ibm.com/support/docview.wss?uid=swg21690725
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98309
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-6170",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-02-02T01:59:02.593",
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21690725",
"tags": [
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98309",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21690725",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98309",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault."
},
{
"lang": "es",
"value": "El nodo HTTPInput en IBM WebSphere Message Broker 7.0 anterior a 7.0.0.8 y 8.0 anterior a 8.0.0.6 y IBM Integration Bus 9.0 anterior a 9.0.0.4 permite a atacantes remotos obtener información sensible mediante la provocación de un fallo SOAP."
}
],
"lastModified": "2026-06-17T00:12:40.543",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:integration_bus:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D9B868C-9348-4D31-95F9-FEC3D91158AE"
},
{
"criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "725E3F95-4096-497D-8F2A-02C185ACF8CB"
},
{
"criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACB80DEF-E09A-4B51-96B8-75F0AD9C6499"
},
{
"criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "576FE339-BD08-4994-B31A-15BC521650E7"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "240F8B7E-D5F2-4450-97D2-45A4E427170D"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F76DCB43-6AFF-4C58-B646-423A6CECCA14"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BC76D23-2211-40D8-8115-382BD7BA6ABD"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD879AA3-9887-4C8F-BEDB-50A39D193C4C"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA01CDC5-5725-460F-9DAD-B7F8094FAA69"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DF45543-2C8E-414B-AB66-10D4B59DDF5C"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2B82976-621B-46A2-960B-BB8E42E75847"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0CF4BE69-414F-4922-89F8-BA904CA2C426"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F93BF57-FD4F-456C-8DFD-CEF8B5AEF35D"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B859DAA9-1B0E-47CE-813D-108776C3B239"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2458C42A-90F7-457C-AAD6-205D9893A993"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BFEC988-5E94-474F-9A60-966B8FA8B8F6"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE5CCF85-8149-43DB-A594-99895D94F447"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA0D7E80-2607-4567-8D1C-2ADA32F174D8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}