Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfpf-55wm-vcv7

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.

EPSS

Процентиль: 80%
0.01418
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 15 лет назад

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.

EPSS

Процентиль: 80%
0.01418
Низкий

Дефекты

CWE-20