CVE-2014-6309

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
12/04/2018
Last modified:
21/04/2021

Description

The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.2:*:*:*:jms:*:*:*
cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.3:*:*:*:jms:*:*:*
cpe:2.3:a:tenefit:kaazing_websocket_gateway:4.0.4:*:*:*:jms:*:*:*