6.8
CVSSv2

CVE-2011-1320

Published: 08/03/2011 Updated: 29/03/2011
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x prior to 6.1.0.35 and 7.x prior to 7.0.0.15, when the Tivoli Integrated Portal / embedded WebSphere Application Server (TIP/eWAS) framework is used, does not properly delete AuthCache entries upon a logout, which might allow remote malicious users to access the server by leveraging an unattended workstation.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server 6.1.0.21

ibm websphere application server 6.1.0.23

ibm websphere application server 6.1.0.1

ibm websphere application server 6.1.0.2

ibm websphere application server 6.1.0.3

ibm websphere application server 6.1.0.0

ibm websphere application server 6.1.0

ibm websphere application server 6.1.0.25

ibm websphere application server 6.1.0.27

ibm websphere application server 6.1.0.29

ibm websphere application server 6.1.0.33

ibm websphere application server 6.1.0.9

ibm websphere application server 6.1.0.12

ibm websphere application server 6.1.0.15

ibm websphere application server 6.1.0.19

ibm websphere application server 6.1.0.17

ibm websphere application server 6.1.0.31

ibm websphere application server 6.1.0.11

ibm websphere application server 6.1.0.5

ibm websphere application server 6.1.0.7

ibm websphere application server 7.0.0.4

ibm websphere application server 7.0.0.3

ibm websphere application server 7.0.0.1

ibm websphere application server 7.0.0.13

ibm websphere application server 7.0.0.5

ibm websphere application server 7.0.0.9

ibm websphere application server 7.0.0.2

ibm websphere application server 7.0

ibm websphere application server 7.0.0.6

ibm websphere application server 7.0.0.7

ibm websphere application server 7.0.0.8

ibm websphere application server 7.0.0.11