Description
IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-7227 | IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password. |
References
| Link | Providers |
|---|---|
| http://www-01.ibm.com/support/docview.wss?uid=swg1PK54565 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T01:40:36.528Z
Reserved: 2011-02-14T00:00:00.000Z
Link: CVE-2008-7274
No data.
Status : Modified
Published: 2011-02-15T01:00:01.227
Modified: 2026-04-29T01:13:23.040
Link: CVE-2008-7274
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD