IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21963275 | |
http://www.securitytracker.com/id/1033384 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21690185 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI29911 | vendor advisory |
http://www.securityfocus.com/bid/71834 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/99009 | vdb entry |