CVE-2012-5952: IBM WebSphere Message Broker

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.

Affected products

  • IBM WebSphere Message Broker: version 6.1 only; version 6.1.0.1 only; version 6.1.0.2 only; version 6.1.0.3 only; version 6.1.0.4 only; version 6.1.0.5 only; …

Published 2013-02-20. Last modified 2026-06-16.