Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2012-5756
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a collective configuration is enabled, has a single secret key that is shared across different customers' installations, which allows remote attackers to spoof a container server by (1) sniffing the network to locate a cleartext transmission of this key or (2) leveraging knowledge of this key from another installation.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM WebSphere DataPower XC10 Appliance 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM WebSphere DataPower XC10是美国IBM公司的一套高速缓存平台。该平台可在对现有应用程序几乎不做任何更改的情况下对数据进行分布式高速缓存。 IBM WebSphere DataPower XC10 Appliance 2.0.0.0至2.0.0.3版本和2.1.0.0至2.1.0.2版本中存在漏洞,该漏洞源于集体配置启用时,程序的一个单一密钥将被不同的客户安装程序所共享。远程攻击者可通过(1)嗅探网络定位该密钥的明文传送或(2)利用来自其他安装程序的该密钥信息利用该漏洞欺骗容器
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2012-5756
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2012-5756
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2012-5756

No comments yet


Leave a comment