Vulnerability Intelligence Report
CVE-2011-1377
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:2.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ibm | websphere_application_server | 6.1, 6.1.0, 6.1.0.0, 6.1.0.1, 6.1.0.2, 6.1.0.3, 6.1.0.5, 6.1.0.7, 6.1.0.9, 6.1.0.11, 6.1.0.12, 6.1.0.15, 6.1.0.17, 6.1.0.19, 6.1.0.21, 6.1.0.23, 6.1.0.25, 6.1.0.27, 6.1.0.29, 6.1.0.31, 6.1.0.33, 6.1.0.35, 6.1.0.37, 6.1.0.39, 6.1.1, 6.1.3, 6.1.5, 6.1.6, 6.1.7, 6.1.13, 6.1.14 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.404%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2011-03-10T00:00:00 |
| Published | 2012-01-15T02:00:00 |
| Patch Date | 2011-10-19 |
| Last Updated | 2024-08-06T22:21:34 |
Community Chatter & Buzz