CVE-2010-3186: Input Validation
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3186?
The severity of CVE-2010-3186 is not explicitly stated, but it affects several versions of the IBM WebSphere Application Server when dealing with WS-Security policies.
How do I fix CVE-2010-3186?
To fix CVE-2010-3186, you should upgrade to the latest patched version of IBM WebSphere Application Server as recommended by IBM.
Which versions of IBM WebSphere Application Server are affected by CVE-2010-3186?
CVE-2010-3186 affects WebSphere Application Server 7.x before 7.0.0.13 and Feature Pack for Web Services versions 6.1.0.9 through 6.1.0.32.
What is the impact of CVE-2010-3186 on applications?
The impact of CVE-2010-3186 involves improper handling of IncludeTimestamp in WS-Security policy, potentially leading to security risks.
Is CVE-2010-3186 related to JAX-WS applications?
Yes, CVE-2010-3186 specifically affects JAX-WS applications using the affected versions of WebSphere Application Server.