Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere应用服务器WSPolicy信息泄露漏洞
Vulnerability Description
IBM Websphere应用服务器以Java和Servlet引擎为基础,支持多种HTTP服务,可帮助用户完成从开发、发布到维护交互式的动态网站的所有工作。 WebSphere应用服务器的Web Services组件没有正确地识别IDAssertion.isUsed绑定属性。如果在使用Web Services组件,且客户端使用ProviderOnly的WSPolicy,并且所使用的简单UserNameToken policyset设置的com.ibm.wsspi.wssecurity.token/IDAs
CVSS Information
N/A
Vulnerability Type
N/A