CVE-2011-4889
Severity CVSS v4.0:
Pending analysis
Type:
CWE-254
Security Features
Publication date:
08/02/2018
Last modified:
21/11/2024
Description
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* | 6.1 (including) | 6.1.0.43 (excluding) |
| cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* | 7.0 (including) | 7.0.0.21 (excluding) |
| cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* | 8.0 (including) | 8.0.0.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



