CVE-2011-4889
08.02.2018, 23:29
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | websphere_application_server | 6.1 ≤ 𝑥 < 6.1.0.43 |
ibm | websphere_application_server | 7.0 ≤ 𝑥 < 7.0.0.21 |
ibm | websphere_application_server | 8.0 ≤ 𝑥 < 8.0.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration