[Forgot Password]
Login  Register Subscribe

23631

 
 

117687

 
 

98218

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2010-3186

Date: (C)2010-08-30   (M)2017-08-18 


IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.

CVSS Score: 10.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
SECUNIA-41173
OSVDB-67570
ADV-2010-2215
http://www-01.ibm.com/support/docview.wss?uid=swg21443736
http://www-01.ibm.com/support/docview.wss?uid=swg24027708
http://www-01.ibm.com/support/docview.wss?uid=swg24027709
websphere-timestamp-unspecified(61435)

CPE    25
cpe:/a:ibm:websphere_application_server:6.1.0.27
cpe:/a:ibm:websphere_application_server:6.1.0.9
cpe:/a:ibm:websphere_application_server:6.1.0.25
cpe:/a:ibm:websphere_application_server:6.1.0.23
...
CWE    1
CWE-20

© 2013 SecPod Technologies