CVE-2011-4889

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
08/02/2018
Last modified:
21/11/2024

Description

The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* 6.1 (including) 6.1.0.43 (excluding)
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* 7.0 (including) 7.0.0.21 (excluding)
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* 8.0 (including) 8.0.0.2 (excluding)