« Volver al listado

CVE-2015-2018

Estado: ModificadaBaja (3.5)—

IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-2018",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-08-23T15:59:00.113",
  "references": [
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07773",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21961734",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07773",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21961734",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en IBM Integration Bus 9 y 10 en versiones anteriores a 10.0.0.1 y WebSphere Message Broker 7 en versiones anteriores a 7.0.0.8 y 8 en versiones anteriores a 8.0.0.7 no asegura que sea seleccionado el perfil de seguridad correcto, lo que permite a usuarios remotos autenticados obtener información sensible a través de vectores no espicificados."
    }
  ],
  "lastModified": "2026-06-17T00:23:27.727",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D9B868C-9348-4D31-95F9-FEC3D91158AE"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92E6A5C9-29C2-458D-AA67-E74945E2012F"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "240F8B7E-D5F2-4450-97D2-45A4E427170D"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F76DCB43-6AFF-4C58-B646-423A6CECCA14"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BC76D23-2211-40D8-8115-382BD7BA6ABD"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD879AA3-9887-4C8F-BEDB-50A39D193C4C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA01CDC5-5725-460F-9DAD-B7F8094FAA69"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DF45543-2C8E-414B-AB66-10D4B59DDF5C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2B82976-621B-46A2-960B-BB8E42E75847"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:7.0.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CF4BE69-414F-4922-89F8-BA904CA2C426"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F93BF57-FD4F-456C-8DFD-CEF8B5AEF35D"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B859DAA9-1B0E-47CE-813D-108776C3B239"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2458C42A-90F7-457C-AAD6-205D9893A993"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BFEC988-5E94-474F-9A60-966B8FA8B8F6"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE5CCF85-8149-43DB-A594-99895D94F447"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA0D7E80-2607-4567-8D1C-2ADA32F174D8"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32E57C58-4A30-43BE-B8CC-E6B38E67AA8C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}