CVE-2014-6138 (websphere_datapower_xc10_appliance_firmware)

The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors.