CVSS2
Attack Vector
LOCAL
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:H/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
5.1%
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | websphere_application_server | 5.1.0 | cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2 | cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.4 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.6 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.8 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.8:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.10 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.10:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.12 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.12:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.14 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.14:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.16 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.16:*:*:*:*:*:*:* |
ibm | websphere_application_server | 6.0.2.18 | cpe:2.3:a:ibm:websphere_application_server:6.0.2.18:*:*:*:*:*:*:* |