Web/Portal Technologies - JDE1 (MOSC)

MOSC Banner

Possible security exposure with WebSphere Application Server with WS-Security enabled applications u

edited Jan 16, 2013 9:39AM in Web/Portal Technologies - JDE1 (MOSC) 2 comments
Possible security exposure with WebSphere Application Server with WS-Security enabled applications using LTPA tokens (PM43585/PM43792/PM45181)



Flash (Alert)


Abstract

There is a possible security exposure when using WS-Security resulting in a user gaining elevated privileges. This impacts applications using either JAX-WS and JAX-RPC.

Content

CVE ID: CVE-2011-1377

Versions affected:

  • WebSphere Application Server, all platforms, Versions 8.0 through 8.0.0.2, 7.0 through 7.0.0.21, and 6.1 through 6.1.0.41, 6.0.2 through 6.0.2.43.
  • WebSphere Application Server Feature Pack for Web Services Versions 6.1.0.9 through 6.1.0.39.

Versions not impacted:
  • For JAX-WS Runtime:
    • WebSphere Application Server Versions 8.0.0.2 and later, and 7.0.0.21 and later.
    • WebShere Application Server Feature Pack for Web Services Versions 6.1.0.41 and later,
  • For JAX-RPC Runtime:
Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center