Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere Application Server Username Token Option 会话劫持漏洞
Vulnerability Description
IBM Websphere应用服务器以Java和Servlet引擎为基础,支持多种HTTP服务,可帮助用户完成从开发、发布到维护交互式的动态网站的所有工作。 IBM WebSphere应用程序服务器修复补丁1 (7.0.0.1)之前的版本7.0版本,修复补丁23 (6.1.0.23)之前的版本6.1版本,以及修复补丁33 (6.0.2.33)之前的版本6.0.2版本中的网络服务安全组件没有适当地执行储存在com.ibm.wsspi.wssecurity.core客户属性的WS-Security键联中的(1
CVSS Information
N/A
Vulnerability Type
N/A