First published: Sat Nov 16 2013(Updated: )
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | =7.0 | |
Ibm Websphere Application Server | =7.0.0.1 | |
Ibm Websphere Application Server | =7.0.0.2 | |
Ibm Websphere Application Server | =7.0.0.3 | |
Ibm Websphere Application Server | =7.0.0.4 | |
Ibm Websphere Application Server | =7.0.0.5 | |
Ibm Websphere Application Server | =7.0.0.6 | |
Ibm Websphere Application Server | =7.0.0.7 | |
Ibm Websphere Application Server | =7.0.0.8 | |
Ibm Websphere Application Server | =7.0.0.9 | |
Ibm Websphere Application Server | =7.0.0.10 | |
Ibm Websphere Application Server | =7.0.0.11 | |
Ibm Websphere Application Server | =7.0.0.12 | |
Ibm Websphere Application Server | =7.0.0.13 | |
Ibm Websphere Application Server | =7.0.0.14 | |
Ibm Websphere Application Server | =7.0.0.15 | |
Ibm Websphere Application Server | =7.0.0.16 | |
Ibm Websphere Application Server | =7.0.0.17 | |
Ibm Websphere Application Server | =7.0.0.18 | |
Ibm Websphere Application Server | =7.0.0.19 | |
Ibm Websphere Application Server | =7.0.0.21 | |
Ibm Websphere Application Server | =7.0.0.22 | |
Ibm Websphere Application Server | =7.0.0.23 | |
Ibm Websphere Application Server | =7.0.0.24 | |
Ibm Websphere Application Server | =7.0.0.25 | |
Ibm Websphere Application Server | =7.0.0.27 | |
Ibm Websphere Application Server | =7.0.0.29 | |
Ibm Websphere Application Server | =8.0.0.0 | |
Ibm Websphere Application Server | =8.0.0.1 | |
Ibm Websphere Application Server | =8.0.0.2 | |
Ibm Websphere Application Server | =8.0.0.3 | |
Ibm Websphere Application Server | =8.0.0.4 | |
Ibm Websphere Application Server | =8.0.0.5 | |
Ibm Websphere Application Server | =8.0.0.6 | |
Ibm Websphere Application Server | =8.0.0.7 | |
Ibm Websphere Application Server | =8.5.0.0 | |
Ibm Websphere Application Server | =8.5.0.1 | |
Ibm Websphere Application Server | =8.5.0.2 | |
Ibm Websphere Application Server | =8.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.