PT-2017-1546 · Ibm · Ibm Websphere Application Server

Published

2017-03-20

·

Updated

2019-10-03

·

CVE-2017-1151

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebSphere Application Server versions 8.0 through 9.0
Description The issue is related to insufficient access control in the OpenID Connect (OIDC) and Trust Association Interceptor (TAI) components of the WebSphere Application Server. This could allow a remote attacker to gain elevated privileges on the system.
Recommendations For versions 8.0 through 9.0, update the configuration to properly restrict access control for OpenID Connect and Trust Association Interceptor components to prevent privilege escalation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00691
CVE-2017-1151

Affected Products

Ibm Websphere Application Server