PT-2010-4626 · Ibm · Ibm Websphere Application Server+1

Published

2010-08-30

·

Updated

2017-08-17

·

CVE-2010-3186

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 7.x before 7.0.0.13 IBM WebSphere Application Server Feature Pack for Web Services versions 6.1.0.9 through 6.1.0.32
Description The issue is related to the handling of the IncludeTimestamp setting in the WS-Security policy when a JAX-WS application is used. This has unspecified impact and allows for remote attack vectors.
Recommendations For IBM WebSphere Application Server versions 7.x before 7.0.0.13, update to version 7.0.0.13 or later. For IBM WebSphere Application Server Feature Pack for Web Services versions 6.1.0.9 through 6.1.0.32, update to a version outside of this range.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3186

Affected Products

Ibm Websphere Application Server
Ibm Websphere Application Server Feature Pack For Web Services