CVE-2014-6176 affects IBM WebSphere Process Server, WebSphere Enterprise Service Bus, and Business Process Manager Advanced, where the SCA module HTTP import binding disregards SSL settings and defaults to SSLv3. This vulnerability, with a CVSS score of 4.3 (medium severity), allows remote attackers to potentially hijack sessions or obtain sensitive information due to the use of weak ciphers. While the attack complexity is medium, it requires no authentication and primarily impacts confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.5.0.0CPE matchmatch criteria | cpe:2.3:a:ibm:business_process_manager:7.5.0.0:*:*:*:advanced:*:*:* | ||
7.5.0.1CPE matchmatch criteria | cpe:2.3:a:ibm:business_process_manager:7.5.0.1:*:*:*:advanced:*:*:* | ||
7.5.1.0CPE matchmatch criteria | cpe:2.3:a:ibm:business_process_manager:7.5.1.0:*:*:*:advanced:*:*:* | ||
7.5.1.1CPE matchmatch criteria | cpe:2.3:a:ibm:business_process_manager:7.5.1.1:*:*:*:advanced:*:*:* | ||
8.0.0.0CPE matchmatch criteria | cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:advanced:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.