Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpph-v39p-r2xx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.

EPSS

Процентиль: 31%
0.00121
Низкий

Связанные уязвимости

nvd
почти 15 лет назад

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.

EPSS

Процентиль: 31%
0.00121
Низкий