Vulnerability Name: | CVE-2010-0563 (CCN-56185) | ||||||||
Assigned: | 2010-02-05 | ||||||||
Published: | 2010-02-05 | ||||||||
Updated: | 2010-11-03 | ||||||||
Summary: | The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0563 Source: CCN Type: SA38425 WebSphere Application Server "Requires SSL" Option Security Issue Source: SECUNIA Type: Vendor Advisory 38425 Source: CCN Type: SECTRACK ID: 1023551 IBM WebSphere Application Server Single Signon Requires SSL Option May Not Be Honored Source: SECTRACK Type: UNKNOWN 1023551 Source: CCN Type: IBM APAR PM00610 Potential security exposure with WebSphere Application Server with "Requires SSL" option of single sign-on (PM00610) Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21417839 Source: AIXAPAR Type: UNKNOWN PM00610 Source: OSVDB Type: UNKNOWN 62140 Source: CCN Type: OSVDB ID: 62140 IBM WebSphere Application Server Single Sign-on Requires SSL Function Weakness Source: BID Type: UNKNOWN 38122 Source: CCN Type: BID-38122 IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability Source: XF Type: UNKNOWN was-requiresssl-weak-security(56185) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |