Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qq9j-3pwq-87gm

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).

EPSS

Процентиль: 55%
0.00321
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 16 лет назад

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).

EPSS

Процентиль: 55%
0.00321
Низкий

Дефекты

CWE-287