IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/82759 | vdb entry vendor advisory |
http://www-01.ibm.com/support/docview.wss?&uid=swg21632423 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM75582 | vendor advisory broken link |