|Date: (C)2012-09-25 (M)2017-08-29|| |
IBM WebSphere Application Server (WAS) 6.1 before 220.127.116.11, 7.0 before 18.104.22.168, 8.0 before 22.214.171.124, and 8.5 before 126.96.36.199, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
|CVSS Score: 6.8||Access Vector: NETWORK|
|Exploit Score: 8.6||Access Complexity: MEDIUM|
|Impact Score: 6.4||Authentication: NONE|
| ||Confidentiality: PARTIAL|
| ||Integrity: PARTIAL|
| ||Availability: PARTIAL|