IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21611313 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/77478 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM66514 | vendor advisory |