CVE-2008-4679
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.
El componente Web Services Security en IBM WebSphere Application Server (WAS) v6.0.2 anterior a v6.0.2.31 y v6.1 anterior a v6.1.0.19, cuando el Certificate Store Collections está configurado para usar las Certificate Revocation Lists (CRL), no llama al método setRevocationEnabled en el objeto PKIXBuilderParameters, que previene el "Java security method" desde la validación del estado de revocación de lso certificados X.509 y permite a atacantes remotos saltarse las restricciones de acceso establecidas a través de un mensaje SOAP con un certificado revocado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-10-22 CVE Reserved
- 2008-10-22 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/31839 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2871 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46002 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg27006876 | 2017-08-08 | |
http://www-01.ibm.com/support/docview.wss?uid=swg27007951 | 2017-08-08 | |
http://www-1.ibm.com/support/docview.wss?uid=swg1PK61258 | 2017-08-08 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32296 | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.1 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.2 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.3 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.5 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.7 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.9 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.9" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.11 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.11" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.13 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.13" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.15 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.15" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.1.17 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.1.17" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.1 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.2 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.3 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.4 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.5 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.6 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.9 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.9" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.11 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.11" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.13 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.13" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.15 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.15" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.17 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.17" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.19 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.19" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.23 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.23" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.25 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.25" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | 6.0.2.27 Search vendor "Ibm" for product "Websphere Application Server" and version "6.0.2.27" | - |
Affected
|