Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g46g-49jm-3qmj

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.

WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.

EPSS

Процентиль: 17%
0.00054
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 17 лет назад

WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.

EPSS

Процентиль: 17%
0.00054
Низкий

Дефекты

CWE-200