First published: Mon Feb 14 2011(Updated: )
IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7274 is considered a critical vulnerability due to its potential to allow unauthorized access without proper authentication.
To mitigate CVE-2008-7274, it's essential to update IBM WebSphere Application Server to a version that has addressed this vulnerability.
CVE-2008-7274 specifically affects IBM WebSphere Application Server version 6.1.0.9 when the JAAS Login functionality is enabled.
CVE-2008-7274 facilitates an internal application hashtable login attack, allowing attackers to access the system without a password.
Yes, due to the nature of the vulnerability, there is a significant risk of data exposure and unauthorized access to sensitive information.