CVE-2012-3325
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote…
Does this matter?
Lower severity and a low EPSS score (1.82%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/54971
- http://secunia.com/advisories/55115
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM71296
- http://www.ibm.com/support/docview.wss?uid=swg21609067Vendor Advisory
- http://www.securityfocus.com/bid/55309
- http://www.securitytracker.com/id?1027462
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77959
- http://secunia.com/advisories/54971
- http://secunia.com/advisories/55115
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM71296
- http://www.ibm.com/support/docview.wss?uid=swg21609067Vendor Advisory
- http://www.securityfocus.com/bid/55309
- http://www.securitytracker.com/id?1027462
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77959
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.