CVE-2011-4889: Critical severity ibm websphere application server feature pack for web services vulnerability
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4889?
CVE-2011-4889 is classified as a moderate severity vulnerability.
How do I fix CVE-2011-4889?
To fix CVE-2011-4889, upgrade IBM WebSphere Application Server to version 6.1.0.43, 7.0.0.21, or 8.0.0.2 or later.
What is the impact of CVE-2011-4889?
CVE-2011-4889 could lead to an inability to properly update passwords in configurations using Tivoli Directory Server.
What versions of IBM WebSphere Application Server are affected by CVE-2011-4889?
CVE-2011-4889 affects IBM WebSphere Application Server versions 6.1 prior to 6.1.0.43, 7.0 prior to 7.0.0.21, and 8.0 prior to 8.0.0.2.
Is CVE-2011-4889 a critical vulnerability?
CVE-2011-4889 is not classified as a critical vulnerability but should still be addressed to prevent potential unauthorized access.