9.8
CVSSv3

CVE-2011-4889

Published: 08/02/2018 Updated: 10/03/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 prior to 6.1.0.43, 7.0 prior to 7.0.0.21, and 8.0 prior to 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote malicious users to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server