PT-2011-3051 · Ibm · Ibm Websphere Application Server+1
Published
2011-03-08
·
Updated
2011-03-29
·
CVE-2011-1320
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server versions 6.1.0.x through 6.1.0.34
IBM WebSphere Application Server versions 7.x through 7.0.0.14
Description
The issue arises when the Tivoli Integrated Portal / embedded WebSphere Application Server framework is used, and the Security component does not properly delete AuthCache entries upon a logout. This might allow remote attackers to access the server by leveraging an unattended workstation.
Recommendations
For IBM WebSphere Application Server versions 6.1.0.x through 6.1.0.34, update to version 6.1.0.35 or later.
For IBM WebSphere Application Server versions 7.x through 7.0.0.14, update to version 7.0.0.15 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server
Ibm Tivoli Integrated Portal