Release date:
Updated on: 2013-03-01
Affected Systems:
IBM WebSphere Message Broker 8.x
IBM WebSphere Message Broker 7.x
IBM WebSphere Message Broker 6.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-5952, CVE-2012-5953, CVE-2013-0466
WebSphere Message Broker is a lightweight and advanced ESB.
WebSphere Message Broker 6.1, 7.0, and 8.0 have multiple security vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions, operate certain data, and cause DOS.
1. An error occurs when processing WS-Addressing and WS-Security requests. Because no basic authentication check is performed, messages without authentication can be sent to the remote server.
2. An error exists in the HTTPInput node, which can trigger an infinite loop. You need to enable the "Parse Query Strings" option for successful exploitation.
3. Some data may be operated due to an error in processing the request of the WSDL file.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: http://secunia.com/advisories/52176/
Http://www-01.ibm.com/support/docview.wss? Uid = swg21623316
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/software/integration/wbimessagebroker/