PT-2021-18454 · Ibm · Ibm Websphere Application Server

Published

2021-06-11

·

Updated

2022-07-12

·

CVE-2021-29754

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 7.0 through 9.0
Description The issue is related to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI) in IBM WebSphere Application Server.
Recommendations For versions 7.0 through 9.0, consider disabling the SAML Web Inbound Trust Association Interceptor (TAI) as a temporary workaround until a patch is available. Restrict access to sensitive areas of the application server to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-29754

Affected Products

Ibm Websphere Application Server