IBM WebSphere Application Server Feature Pack Security Bypass Vulnerability
RISK: Medium Risk
TYPE: Servers - Internet App Servers
A vulnerability has been identified in IBM WebSphere Application Server Feature Pack for Web Services, which can be exploited by malicious users to bypass certain security restrictions. An error related to LPTA tokens in a WS-Security policy enabled Java API for XML Web Services (JAX-WS) application can be exploited to gain the same identity as a previously processed LTPA token.
Impact
- Security Restriction Bypass
System / Technologies affected
- IBM WebSphere Application Server Feature Pack for Web Services 6.1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply Interim Fix (APAR PM43792) or Fix Pack 43 (6.1.0.43).
Vulnerability Identifier
Source
Related Link
Share with