← Back

CVE-2011-1312

nvd nist
Published: Mar 8, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.

Affected (30)

1 product
Websphere Application Server
Configuration A
18 vulnerable
Configuration B
12 vulnerable

Related CWEs

Timeline

No history available yet.