Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-1311

Overview

Vulnerability Score 6.0 6.0
CVE Id CVE-2011-1311
Last Modified 07 Apr 2011 12:00:00
Published 08 Mar 2011 04:59:34
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication SINGLE_INSTANCE

CVE-2011-1311

Summary

The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances by requesting a service.

Vulnerable Systems

Application

  • Ibm Websphere Application Server 2.0

  • Ibm Websphere Application Server 3.0

  • Ibm Websphere Application Server 3.0.2

  • Ibm Websphere Application Server 3.0.2.1

  • Ibm Websphere Application Server 3.0.2.2

  • Ibm Websphere Application Server 3.0.2.3

  • Ibm Websphere Application Server 3.0.2.4

  • Ibm Websphere Application Server 3.0.21

  • Ibm Websphere Application Server 3.5

  • Ibm Websphere Application Server 3.5.1

  • Ibm Websphere Application Server 3.5.2

  • Ibm Websphere Application Server 3.5.3

  • Ibm Websphere Application Server 3.52

  • Ibm Websphere Application Server 4.0.1

  • Ibm Websphere Application Server 4.0.2

  • Ibm Websphere Application Server 4.0.3

  • Ibm Websphere Application Server 4.0.4

  • Ibm Websphere Application Server 5.0

  • Ibm Websphere Application Server 5.0.0

  • Ibm Websphere Application Server 5.0.1

  • Ibm Websphere Application Server 5.0.2

  • Ibm Websphere Application Server 5.0.2.1

  • Ibm Websphere Application Server 5.0.2.10

  • Ibm Websphere Application Server 5.0.2.11

  • Ibm Websphere Application Server 5.0.2.12

  • Ibm Websphere Application Server 5.0.2.13

  • Ibm Websphere Application Server 5.0.2.14

  • Ibm Websphere Application Server 5.0.2.15

  • Ibm Websphere Application Server 5.0.2.16

  • Ibm Websphere Application Server 5.0.2.2

  • Ibm Websphere Application Server 5.0.2.3

  • Ibm Websphere Application Server 5.0.2.4

  • Ibm Websphere Application Server 5.0.2.5

  • Ibm Websphere Application Server 5.0.2.6

  • Ibm Websphere Application Server 5.0.2.7

  • Ibm Websphere Application Server 5.0.2.8

  • Ibm Websphere Application Server 5.0.2.9

  • Ibm Websphere Application Server 5.1.0

  • Ibm Websphere Application Server 5.1.0.2

  • Ibm Websphere Application Server 5.1.0.3

  • Ibm Websphere Application Server 5.1.0.4

  • Ibm Websphere Application Server 5.1.0.5

  • Ibm Websphere Application Server 5.1.1

  • Ibm Websphere Application Server 5.1.1.1

  • Ibm Websphere Application Server 5.1.1.10

  • Ibm Websphere Application Server 5.1.1.11

  • Ibm Websphere Application Server 5.1.1.12

  • Ibm Websphere Application Server 5.1.1.13

  • Ibm Websphere Application Server 5.1.1.14

  • Ibm Websphere Application Server 5.1.1.15

  • Ibm Websphere Application Server 5.1.1.16

  • Ibm Websphere Application Server 5.1.1.17

  • Ibm Websphere Application Server 5.1.1.2

  • Ibm Websphere Application Server 5.1.1.3

  • Ibm Websphere Application Server 5.1.1.4

  • Ibm Websphere Application Server 5.1.1.5

  • Ibm Websphere Application Server 5.1.1.6

  • Ibm Websphere Application Server 5.1.1.7

  • Ibm Websphere Application Server 5.1.1.8

  • Ibm Websphere Application Server 5.1.1.9

  • Ibm Websphere Application Server 6.0

  • Ibm Websphere Application Server 6.0.0.1

  • Ibm Websphere Application Server 6.0.0.2

  • Ibm Websphere Application Server 6.0.0.3

  • Ibm Websphere Application Server 6.0.1

  • Ibm Websphere Application Server 6.0.1.1

  • Ibm Websphere Application Server 6.0.1.11

  • Ibm Websphere Application Server 6.0.1.13

  • Ibm Websphere Application Server 6.0.1.15

  • Ibm Websphere Application Server 6.0.1.17

  • Ibm Websphere Application Server 6.0.1.2

  • Ibm Websphere Application Server 6.0.1.3

  • Ibm Websphere Application Server 6.0.1.5

  • Ibm Websphere Application Server 6.0.1.7

  • Ibm Websphere Application Server 6.0.1.9

  • Ibm Websphere Application Server 6.0.2

  • Ibm Websphere Application Server 6.0.2.1

  • Ibm Websphere Application Server 6.0.2.11

  • Ibm Websphere Application Server 6.0.2.13

  • Ibm Websphere Application Server 6.0.2.15

  • Ibm Websphere Application Server 6.0.2.17

  • Ibm Websphere Application Server 6.0.2.19

  • Ibm Websphere Application Server 6.0.2.2

  • Ibm Websphere Application Server 6.0.2.22

  • Ibm Websphere Application Server 6.0.2.23

  • Ibm Websphere Application Server 6.0.2.24

  • Ibm Websphere Application Server 6.0.2.25

  • Ibm Websphere Application Server 6.0.2.27

  • Ibm Websphere Application Server 6.0.2.28

  • Ibm Websphere Application Server 6.0.2.29

  • Ibm Websphere Application Server 6.0.2.3

  • Ibm Websphere Application Server 6.0.2.30

  • Ibm Websphere Application Server 6.0.2.31

  • Ibm Websphere Application Server 6.0.2.32

  • Ibm Websphere Application Server 6.0.2.4

  • Ibm Websphere Application Server 6.0.2.5

  • Ibm Websphere Application Server 6.0.2.6

  • Ibm Websphere Application Server 6.0.2.7

  • Ibm Websphere Application Server 6.0.2.9

  • Ibm Websphere Application Server 6.1

  • Ibm Websphere Application Server 6.1.0

  • Ibm Websphere Application Server 6.1.0.0

  • Ibm Websphere Application Server 6.1.0.1

  • Ibm Websphere Application Server 6.1.0.11

  • Ibm Websphere Application Server 6.1.0.12

  • Ibm Websphere Application Server 6.1.0.15

  • Ibm Websphere Application Server 6.1.0.17

  • Ibm Websphere Application Server 6.1.0.19

  • Ibm Websphere Application Server 6.1.0.2

  • Ibm Websphere Application Server 6.1.0.21

  • Ibm Websphere Application Server 6.1.0.23

  • Ibm Websphere Application Server 6.1.0.25

  • Ibm Websphere Application Server 6.1.0.27

  • Ibm Websphere Application Server 6.1.0.29

  • Ibm Websphere Application Server 6.1.0.3

  • Ibm Websphere Application Server 6.1.0.31

  • Ibm Websphere Application Server 6.1.0.33

  • Ibm Websphere Application Server 6.1.0.5

  • Ibm Websphere Application Server 6.1.0.7

  • Ibm Websphere Application Server 6.1.0.9

  • Ibm Websphere Application Server 6.1.1

  • Ibm Websphere Application Server 6.1.13

  • Ibm Websphere Application Server 6.1.14

  • Ibm Websphere Application Server 6.1.3

  • Ibm Websphere Application Server 6.1.5

  • Ibm Websphere Application Server 6.1.6

  • Ibm Websphere Application Server 6.1.7

  • Ibm Websphere Application Server 7.0

  • Ibm Websphere Application Server 7.0.0.1

  • Ibm Websphere Application Server 7.0.0.11

  • Ibm Websphere Application Server 7.0.0.13

  • Ibm Websphere Application Server 7.0.0.2

  • Ibm Websphere Application Server 7.0.0.3

  • Ibm Websphere Application Server 7.0.0.4

  • Ibm Websphere Application Server 7.0.0.5

  • Ibm Websphere Application Server 7.0.0.6

  • Ibm Websphere Application Server 7.0.0.7

  • Ibm Websphere Application Server 7.0.0.8

  • Ibm Websphere Application Server 7.0.0.9


References

CONFIRM - http://www-01.ibm.com/support/docview.wss?uid=swg27014463

AIXAPAR - PM25455


Last Updated: 27 May 2016 10:56:16