CVE-2006-6136: Critical severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
Published Nov 28, 2006
·Updated
IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.
Affected Software
1 affected component
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0
Remediation
Patch Available
Event History
Nov 28, 2006
CVE Published
02:07 AM
Data Sourced
via NVD·02:07 AM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6136?
The severity of CVE-2006-6136 is currently unknown due to lack of documented attack vectors.
2
How do I fix CVE-2006-6136?
To fix CVE-2006-6136, upgrade to IBM WebSphere Application Server version 6.1.0.3 or later.
3
What products are affected by CVE-2006-6136?
CVE-2006-6136 affects IBM WebSphere Application Server version 6.1.0 before Fix Pack 3.
4
What types of attacks could occur due to CVE-2006-6136?
The potential attack types for CVE-2006-6136 are currently undocumented and not clearly defined.
5
What is EAL4 authentication in relation to CVE-2006-6136?
EAL4 authentication refers to a specific level of assurance in security checking, which is not properly enforced in the vulnerable versions of IBM WebSphere.