CVE-2011-1312: Medium severity ibm websphere application server feature pack for web services vulnerability
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1312?
CVE-2011-1312 has a high severity rating due to its potential to allow remote authenticated administrators to bypass restrictions.
How do I fix CVE-2011-1312?
To fix CVE-2011-1312, upgrade IBM WebSphere Application Server to version 6.1.0.31 or 7.0.0.15 or later.
Which versions of IBM WebSphere Application Server are affected by CVE-2011-1312?
CVE-2011-1312 affects IBM WebSphere Application Server versions 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15.
What types of access does CVE-2011-1312 allow for exploitation?
CVE-2011-1312 allows remote authenticated administrators to modify the primary admin ID, leading to unauthorized access.
Is there a workaround for CVE-2011-1312?
There is no official workaround for CVE-2011-1312, so applying the patch or upgrade is necessary for proper mitigation.