Weak Password Update Vulnerability in IBM WebSphere Application Server

Weak Password Update Vulnerability in IBM WebSphere Application Server

CVE-2011-4889 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.

Learn more about our Cis Benchmark Audit For Ibm I.