IBM WebSphere Application Server JAX-RPC WS-Security/JAX-WS Runtime Security Bypass Vulnerability
14 Jul. 2012
Summary
IBM WebSphere Application Server (WAS) is prone to a security-bypass vulnerability because the application fails to properly handle WebServices PKCS#7 and PKIPath tokenS.
Vulnerable Systems:
* IBM Websphere Application Server 7.0 3 and prior
Successful exploits may allow attackers to gain unauthorized access to the service, which may lead to other attacks.
The following are vulnerable:
WebSphere Application Server prior to 6.0.2.41, 6.1.0.31, and 7.0.0.11.