CVE-2011-1377
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.32% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- ibm/websphere application server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/46469Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM43792
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM50205
- http://www-01.ibm.com/support/docview.wss?uid=swg27011716
- http://www.securityfocus.com/bid/50310
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72299
- http://secunia.com/advisories/46469Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM43792
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM50205
- http://www-01.ibm.com/support/docview.wss?uid=swg27011716
- http://www.securityfocus.com/bid/50310
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72299
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.