CVE-2014-0852: IBM WebSphere Datapower Soa Appliance
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel timing attack.
Affected products
- IBM WebSphere Datapower Soa Appliance
- IBM WebSphere Datapower Soa Appliance Firmware: up to and including 4.0.2.15; version 5.0.0 only; version 6.0.0 only; version 6.0.1 only
Published 2014-08-16. Last modified 2026-06-17.