CVE-2011-4889
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.68% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72581VDB Entry, Vendor Advisory
- https://www-304.ibm.com/support/docview.wss?uid=swg21587015Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72581VDB Entry, Vendor Advisory
- https://www-304.ibm.com/support/docview.wss?uid=swg21587015Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.