CVE-2011-1377
published 2012-01-15CVE-2011-1377: The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.40%
82.3th percentile
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hfwj-43j6-7v2f: The Web Services Security component in the Web Services Feature Pack before 6
ghsa_unreviewed·2022-05-17
CVE-2011-1377 [HIGH] GHSA-hfwj-43j6-7v2f: The Web Services Security component in the Web Services Feature Pack before 6
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
GHSA
GHSA-fm76-74p2-rjp6: IBM WebSphere Application Server (WAS) 7
ghsa_unreviewed·2022-05-05·CVSS 10.0
CVE-2013-0482 [CRITICAL] GHSA-fm76-74p2-rjp6: IBM WebSphere Application Server (WAS) 7
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/46469http://www-01.ibm.com/support/docview.wss?uid=swg1PM43792http://www-01.ibm.com/support/docview.wss?uid=swg1PM50205http://www-01.ibm.com/support/docview.wss?uid=swg27011716http://www.securityfocus.com/bid/50310https://exchange.xforce.ibmcloud.com/vulnerabilities/72299http://secunia.com/advisories/46469http://www-01.ibm.com/support/docview.wss?uid=swg1PM43792http://www-01.ibm.com/support/docview.wss?uid=swg1PM50205http://www-01.ibm.com/support/docview.wss?uid=swg27011716http://www.securityfocus.com/bid/50310https://exchange.xforce.ibmcloud.com/vulnerabilities/72299
2012-01-15
Published