CVE-2011-1321: Medium severity ibm websphere application server feature pack for web services vulnerability
The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 does not purge a user from the PlatformCredential cache, which might allow remote authenticated users to gain privileges by leveraging a group membership specified in an old RACF Object (aka RACO).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1321?
CVE-2011-1321 is classified as a medium severity vulnerability due to potential privilege escalation.
How do I fix CVE-2011-1321?
To fix CVE-2011-1321, upgrade IBM WebSphere Application Server to version 6.1.0.37 or 7.0.0.15 or later.
What software versions are affected by CVE-2011-1321?
CVE-2011-1321 affects IBM WebSphere Application Server versions 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15.
What impact does CVE-2011-1321 have on systems?
CVE-2011-1321 may allow remote authenticated users to gain additional privileges by exploiting cached credentials.
Is there a workaround for CVE-2011-1321?
Currently, the recommended action for CVE-2011-1321 is to apply the official patches as no effective workaround is documented.