First published: Thu Jun 10 2021(Updated: )
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | >=7.0.0.0<7.0.0.45 | |
Ibm Websphere Application Server | >=8.0.0.0<8.0.0.15 | |
Ibm Websphere Application Server | >=8.5.0.0<8.5.5.20 | |
Ibm Websphere Application Server | >=9.0.0.0<9.0.5.8 | |
HP HP-UX | ||
IBM AIX | ||
IBM i | ||
Ibm Z\/os | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris | ||
<=9.0 | ||
<=8.5 | ||
<=8.0 | ||
<=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-29754.
The severity of CVE-2021-29754 is high with a score of 8.8.
IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 are affected.
To fix the vulnerability, update your IBM WebSphere Application Server to a version that is not vulnerable.
More information about CVE-2021-29754 can be found at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/202006) and [link2](https://www.ibm.com/support/pages/node/6462627).