Vulnerability Name: CVE-2012-3325 (CCN-77959) Assigned: 2012-08-28 Published: 2012-08-28 Updated: 2017-08-29 Summary: IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors. CVSS v3 Severity: 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P )4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
6.0 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P )4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-20 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2012-3325 Source: CCN Type: SA50471IBM WebSphere Application Server Administrative Access Security Bypass Vulnerability Source: CCN Type: SA51306IBM Intelligent Operations Center Administrative Access Security Bypass Vulnerability Source: CCN Type: SA53006IBM Tivoli System Automation Application Manager Multiple Vulnerabilities Source: CCN Type: SA54971IBM Tivoli Integrated Portal Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN54971 Source: CCN Type: SA55115IBM Tivoli Dynamic Workload Console Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN55115 Source: AIXAPAR Type: UNKNOWNPM71296 Source: CCN Type: IBM Security Bulletin 1609067Potential security exposure with IBM WebSphere Application Server after installing PM44303 Source: CCN Type: IBM Security Bulletin 1611313Security Vulnerabilities fixed in IBM WebSphere Application Server 7.0.0.25 Source: CCN Type: IBM Security Bulletin 1614265Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.0.1 Source: CCN Type: IBM Security Bulletin 1616337Potential security exposure with IBM Rational Developer for System z after installing PM44303 for WebSphere Application Server Source: CCN Type: IBM Security Bulletin 1620517Tivoli Federated Identity Manager Potential security exposure with IBM WebSphere Application Server APAR PM44303 (CVE-2012-3325) Source: CCN Type: IBM Security Bulletin 1621420IBM Service Delivery Manager security exposure after installing PM44303 for WebSphere Application Server (CVE-2012-3325) Source: CCN Type: IBM Security Bulletin 1633992Security Bulletin: Tivoli System Automation Application Mgr 3.2.2 (WAS) Source: CCN Type: IBM Security Bulletin 1642791IBM WebSphere Appliance Management Center, multiple security vulnerabilities in IBM Tivoli Integrated Portal Source: CCN Type: IBM Security Bulletin 1646292Tivoli Business Service Manager - Websphere Potential security exposure(CVE-2012-3325) and Apache Tomcat hash denial of service (CVE-2011-4858) Source: CCN Type: IBM Security Bulletin 1646446Security Vulnerabilities addressed in IBM Tivoli Netcool Performance Manager (CVE-2013-0464, CVE-2012-3325, CVE-2012-3325) Source: CCN Type: IBM Security Bulletin 1646503Tivoli Storage Productivity Center, multiple security vulnerabilities in IBM Tivoli Integrated Portal (CVE-2013-0464, CVE-2012-3325, CVE-2011-4858) Source: CCN Type: IBM Security Bulletin 1646737Potential Security issue for SmartCloud Cost Management (CVE-2013-0464 and CVE-2012-3325) Source: CCN Type: IBM Security Bulletin 1650482IBM Tivoli Key Lifecycle Manager can be affected by multiple vulnerabilities in IBM Tivoli Integrated Portal (CVE-2013-0464, CVE-2012-3325, CVE-2011-4858) Source: CCN Type: IBM Security Bulletin 1651284Tivoli Workload Dynamic Console Vulnerability exposure in Tivoli Integrated Portal component Source: CCN Type: IBM Security Bulletin 1654075Tivoli Netcool/OMNIbus Web GUI - IBM WebSphere Application Server PM44303 security bypass (CVE-2012-3325) and Hash denial of service (CVE-2011-4858) Source: CCN Type: IBM Interim Fix PO00087IBM Intelligent Operations Center interim fix PO00087 Source: CONFIRM Type: Vendor Advisoryhttp://www.ibm.com/support/docview.wss?uid=swg21609067 Source: CCN Type: IBM Security Bulletin 1666077Security Access Manager for Enterprise Single Sign-On can be affected by a vulnerability in WebSphere Application Server (CVE-2014-0411) Source: CCN Type: IBM Security Bulletin 1667352IBM Security Directory Server can be affected by a vulnerability in IBM WebSphere Application Server (CVE-2014-0411) Source: CCN Type: IBM Security Bulletin 1678544IBM Security Directory Server can be affected by a vulnerability in IBM Runtime Environment, JavaTM Technology Edition Versions 5 and 6 (CVE 2014-0160) Source: BID Type: UNKNOWN55309 Source: CCN Type: BID-55309IBM WebSphere Application Server Administrative Access Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN1027462 Source: XF Type: UNKNOWNwas-pm44303-security-bypass(77959) Source: XF Type: UNKNOWNwas-pm44303-security-bypass(77959) Source: CCN Type: IBM Security Bulletin 1611311Security Vulnerabilities fixed in IBM WebSphere Application Server 6.1.0.45 Source: CCN Type: IBM Security Bulletin 1618044Potential security exposure from IBM WebSphere Application Server impacts Rational Application Developer Source: CCN Type: IBM Security Bulletin 1672584IBM Tivoli Directory Integrator can be affected by a vulnerability in IBM Runtime Environment, Java(TM) Technology Edition, Versions 5, 6 and 7 (CVE-2014-0411) Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.12:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.15:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.17:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.19:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.21:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.23:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.25:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.27:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.29:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.31:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.33:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.35:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.37:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.39:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.41:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.43:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.7:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.13:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.14:*:*:*:*:*:*:* Configuration 2 :cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.8:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:* Configuration 3 :cpe:/a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:websphere_application_server:6.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:* AND cpe:/a:ibm:tivoli_federated_identity_manager:6.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_federated_identity_manager:6.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_federated_identity_manager:6.2.0.12:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_federated_identity_manager:6.2.2:*:*:*:*:*:*:* OR cpe:/a:ibm:intelligent_operations_center:1.5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_developer_for_system_z:7.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_developer_for_system_z:8.0.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_developer_for_system_z:8.5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:service_delivery_manager:7.2.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:service_delivery_manager:7.2.2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_business_service_manager:4.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_key_lifecycle_manager:2.0.1:*:*:*:*:*:*:* OR cpe:/o:ibm:security_access_manager:8.2:*:enterprise_single_sign-on:*:*:*:*:* OR cpe:/a:ibm:security_directory_server:6.1:*:*:*:*:*:*:* OR cpe:/a:ibm:security_directory_server:6.2:*:*:*:*:*:*:* OR cpe:/a:ibm:security_directory_server:6.3:*:*:*:*:*:*:* OR cpe:/a:ibm:security_directory_server:6.3.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm websphere application server 6.1
ibm websphere application server 6.1.0
ibm websphere application server 6.1.0.0
ibm websphere application server 6.1.0.1
ibm websphere application server 6.1.0.2
ibm websphere application server 6.1.0.3
ibm websphere application server 6.1.0.5
ibm websphere application server 6.1.0.7
ibm websphere application server 6.1.0.9
ibm websphere application server 6.1.0.11
ibm websphere application server 6.1.0.12
ibm websphere application server 6.1.0.15
ibm websphere application server 6.1.0.17
ibm websphere application server 6.1.0.19
ibm websphere application server 6.1.0.21
ibm websphere application server 6.1.0.23
ibm websphere application server 6.1.0.25
ibm websphere application server 6.1.0.27
ibm websphere application server 6.1.0.29
ibm websphere application server 6.1.0.31
ibm websphere application server 6.1.0.33
ibm websphere application server 6.1.0.35
ibm websphere application server 6.1.0.37
ibm websphere application server 6.1.0.39
ibm websphere application server 6.1.0.41
ibm websphere application server 6.1.0.43
ibm websphere application server 6.1.1
ibm websphere application server 6.1.3
ibm websphere application server 6.1.5
ibm websphere application server 6.1.6
ibm websphere application server 6.1.7
ibm websphere application server 6.1.13
ibm websphere application server 6.1.14
ibm websphere application server 7.0
ibm websphere application server 7.0.0.1
ibm websphere application server 7.0.0.2
ibm websphere application server 7.0.0.3
ibm websphere application server 7.0.0.4
ibm websphere application server 7.0.0.5
ibm websphere application server 7.0.0.6
ibm websphere application server 7.0.0.7
ibm websphere application server 7.0.0.8
ibm websphere application server 7.0.0.9
ibm websphere application server 7.0.0.11
ibm websphere application server 7.0.0.13
ibm websphere application server 7.0.0.15
ibm websphere application server 7.0.0.17
ibm websphere application server 7.0.0.19
ibm websphere application server 7.0.0.21
ibm websphere application server 7.0.0.23
ibm websphere application server 8.0.0.0
ibm websphere application server 8.0.0.1
ibm websphere application server 8.0.0.2
ibm websphere application server 8.0.0.3
ibm websphere application server 8.0.0.4
ibm websphere application server 8.5.0.0
ibm websphere application server 6.0
ibm websphere application server 6.1
ibm websphere application server 7.0
ibm websphere application server 8.0
ibm websphere application server 8.5
ibm tivoli federated identity manager 6.1.1
ibm tivoli federated identity manager 6.2.1
ibm tivoli federated identity manager 6.2.0.12
ibm tivoli federated identity manager 6.2.2
ibm intelligent operations center 1.5.0
ibm rational developer for system z 7.1
ibm rational developer for system z 8.0.1.0
ibm rational developer for system z 8.5.0
ibm service delivery manager 7.2.1.0
ibm service delivery manager 7.2.2.0
ibm tivoli business service manager 4.2.1
ibm tivoli key lifecycle manager 2.0.1
ibm security access manager for enterprise single sign-on 8.2
ibm security directory server 6.1
ibm security directory server 6.2
ibm security directory server 6.3
ibm security directory server 6.3.1