CVE-2014-3060: IBM WebSphere Datapower XC10 Appliance

High severity, CVSS 10.0. EPSS: 2.4% chance of exploitation in the next 30 days.

Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie.

Affected products

  • IBM WebSphere Datapower XC10 Appliance
  • IBM WebSphere Datapower XC10 Appliance Firmware: version 2.5.0.0 only

Published 2014-10-02. Last modified 2026-06-17.