Possible security exposure with WebSphere Application Server with WS-Security enabled applications u
Possible security exposure with WebSphere Application Server with WS-Security enabled applications using LTPA tokens (PM43585/PM43792/PM45181)
Versions not impacted:
Flash (Alert)
Abstract
There is a possible security exposure when using WS-Security resulting in a user gaining elevated privileges. This impacts applications using either JAX-WS and JAX-RPC.
Content
CVE ID: CVE-2011-1377
Versions affected:
- WebSphere Application Server, all platforms, Versions 8.0 through 8.0.0.2, 7.0 through 7.0.0.21, and 6.1 through 6.1.0.41, 6.0.2 through 6.0.2.43.
- WebSphere Application Server Feature Pack for Web Services Versions 6.1.0.9 through 6.1.0.39.
Versions not impacted:
- For JAX-WS Runtime:
- WebSphere Application Server Versions 8.0.0.2 and later, and 7.0.0.21 and later.
- WebShere Application Server Feature Pack for Web Services Versions 6.1.0.41 and later,
- For JAX-RPC Runtime:
Tagged:
0