First published: Tue Mar 08 2011(Updated: )
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | =6.1.0.21 | |
IBM WebSphere Application Server | =6.1.0.19 | |
IBM WebSphere Application Server | =6.1.0.2 | |
IBM WebSphere Application Server | =6.1.0.25 | |
IBM WebSphere Application Server | =6.1.0.11 | |
IBM WebSphere Application Server | =6.1.0.9 | |
IBM WebSphere Application Server | =6.1.0.0 | |
IBM WebSphere Application Server | =6.1.0.1 | |
IBM WebSphere Application Server | =6.1.0.27 | |
IBM WebSphere Application Server | =6.1.0.29 | |
IBM WebSphere Application Server | =6.1.0.7 | |
IBM WebSphere Application Server | =6.1.0.3 | |
IBM WebSphere Application Server | =6.1.0.17 | |
IBM WebSphere Application Server | =6.1.0.15 | |
IBM WebSphere Application Server | =6.1.0.23 | |
IBM WebSphere Application Server | =6.1.0 | |
IBM WebSphere Application Server | =6.1.0.5 | |
IBM WebSphere Application Server | =6.1.0.12 | |
IBM WebSphere Application Server | =7.0.0.2 | |
IBM WebSphere Application Server | =7.0.0.5 | |
IBM WebSphere Application Server | =7.0.0.9 | |
IBM WebSphere Application Server | =7.0.0.4 | |
IBM WebSphere Application Server | =7.0.0.11 | |
IBM WebSphere Application Server | =7.0 | |
IBM WebSphere Application Server | =7.0.0.8 | |
IBM WebSphere Application Server | =7.0.0.6 | |
IBM WebSphere Application Server | =7.0.0.7 | |
IBM WebSphere Application Server | =7.0.0.13 | |
IBM WebSphere Application Server | =7.0.0.3 | |
IBM WebSphere Application Server | =7.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1312 has a high severity rating due to its potential to allow remote authenticated administrators to bypass restrictions.
To fix CVE-2011-1312, upgrade IBM WebSphere Application Server to version 6.1.0.31 or 7.0.0.15 or later.
CVE-2011-1312 affects IBM WebSphere Application Server versions 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15.
CVE-2011-1312 allows remote authenticated administrators to modify the primary admin ID, leading to unauthorized access.
There is no official workaround for CVE-2011-1312, so applying the patch or upgrade is necessary for proper mitigation.