Published: 30-08-2010
Updated: 10-09-2010
Product:
ibm: websphere_application_server 6.1.0.10
ibm: websphere_application_server 6.1.0.11
ibm: websphere_application_server 6.1.0.12
ibm: websphere_application_server 6.1.0.13
ibm: websphere_application_server 6.1.0.14
ibm: websphere_application_server 6.1.0.15
ibm: websphere_application_server 6.1.0.16
ibm: websphere_application_server 6.1.0.17
ibm: websphere_application_server 6.1.0.18
ibm: websphere_application_server 6.1.0.19
ibm: websphere_application_server 6.1.0.20
ibm: websphere_application_server 6.1.0.21
ibm: websphere_application_server 6.1.0.22
ibm: websphere_application_server 6.1.0.23
ibm: websphere_application_server 6.1.0.24
ibm: websphere_application_server 6.1.0.25
ibm: websphere_application_server 6.1.0.26
ibm: websphere_application_server 6.1.0.27
ibm: websphere_application_server 6.1.0.29
ibm: websphere_application_server 6.1.0.31
ibm: websphere_application_server 6.1.0.32
ibm: websphere_application_server 6.1.0.9
ibm: websphere_application_server 7.0
ibm: websphere_application_server 7.0.0.1
ibm: websphere_application_server 7.0.0.10
ibm: websphere_application_server 7.0.0.11
ibm: websphere_application_server 7.0.0.2
ibm: websphere_application_server 7.0.0.3
ibm: websphere_application_server 7.0.0.4
ibm: websphere_application_server 7.0.0.5
ibm: websphere_application_server 7.0.0.6
ibm: websphere_application_server 7.0.0.7
ibm: websphere_application_server 7.0.0.9
Severity: High (10.0)
CVSS vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Potential loss type: Integrity, Confidentiality, Availability
Vulnerability description:
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.
Patch available: No
References:
CONFIRM: http://www-01.ibm.com/support/docview.wss?uid=swg24027709
CONFIRM: http://www-01.ibm.com/support/docview.wss?uid=swg24027708
CONFIRM: http://www-01.ibm.com/support/docview.wss?uid=swg21443736
SECUNIA: http://secunia.com/advisories/41173
