The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-03-31T10:00:00

Updated: 2014-10-20T13:57:00

Reserved: 2009-03-30T00:00:00


Link: CVE-2009-1172

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-03-31T14:09:53.813

Modified: 2014-10-24T05:37:33.447


Link: CVE-2009-1172

JSON object: View

cve-icon Redhat Information

No data.

CWE