CVE-2011-1377: Critical severity ibm websphere application server feature pack for web services vulnerability
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1377?
CVE-2011-1377 has an unspecified impact and attack vectors, noted in the IBM advisory.
How do I fix CVE-2011-1377?
To fix CVE-2011-1377, upgrade to IBM WebSphere Application Server version 6.1.0.41 or later.
Which versions of IBM WebSphere Application Server are affected by CVE-2011-1377?
CVE-2011-1377 affects multiple versions of IBM WebSphere Application Server 6.1, including all subversions prior to 6.1.0.41.
What security feature is mishandled in CVE-2011-1377?
CVE-2011-1377 involves a mishandling of the WS-Security enabling for JAX-WS applications.
Is there a workaround available for CVE-2011-1377?
The primary mitigation for CVE-2011-1377 is to upgrade to a patched version of the software, as no specific workaround is mentioned.