Vulnerability Name:
CVE-2008-2550 (CCN-42822)
Assigned:
2008-06-02
Published:
2008-06-02
Updated:
2017-08-08
Summary:
Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.
CVSS v3 Severity:
10.0 Critical
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
3.7 Low
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
9.3 High
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C
)
6.9 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Type:
CWE-noinfo
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2008-2550
Source: CCN
Type: SA30526
IBM WebSphere Application Server Web Services Unspecified Vulnerability
Source: SECUNIA
Type: Vendor Advisory
30526
Source: CCN
Type: SECTRACK ID: 1020168
IBM WebSphere Unspecified SOAP Security Header Flaw Has Unspecified Impact
Source: CCN
Type: IBM APAR PK61315
Attribute in SOAP security header may cause security exposure
Source: CCN
Type: IBM Support & downloads
Fix list for IBM WebSphere Application Server version 6.1
Source: CONFIRM
Type: UNKNOWN
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27007951
Source: AIXAPAR
Type: UNKNOWN
PK61315
Source: CCN
Type: OSVDB ID: 45961
IBM WebSphere Application Server (WAS) SOAP Security Header Unspecified Exposure
Source: SECTRACK
Type: UNKNOWN
1020168
Source: VUPEN
Type: UNKNOWN
ADV-2008-1734
Source: XF
Type: UNKNOWN
websphere-soap-security-exposure(42822)
Source: XF
Type: UNKNOWN
websphere-soap-information-disclosure(42822)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.0:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.8:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.9:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.10:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.11:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.12:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.13:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.14:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1.0.15:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
(Version <= 6.1.0.16)
Configuration CCN 1
:
cpe:/a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
ibm
websphere application server 6.1
ibm
websphere application server 6.1.0
ibm
websphere application server 6.1.0.0
ibm
websphere application server 6.1.0.1
ibm
websphere application server 6.1.0.2
ibm
websphere application server 6.1.0.3
ibm
websphere application server 6.1.0.4
ibm
websphere application server 6.1.0.5
ibm
websphere application server 6.1.0.6
ibm
websphere application server 6.1.0.7
ibm
websphere application server 6.1.0.8
ibm
websphere application server 6.1.0.9
ibm
websphere application server 6.1.0.10
ibm
websphere application server 6.1.0.11
ibm
websphere application server 6.1.0.12
ibm
websphere application server 6.1.0.13
ibm
websphere application server 6.1.0.14
ibm
websphere application server 6.1.0.15
ibm
websphere application server *
ibm
websphere application server 6.0.2
ibm
websphere application server 6.1