IBM WebSphere Portal Server Remote Administration Authentication Bypass Vulnerability
BID:30500
Info
IBM WebSphere Portal Server Remote Administration Authentication Bypass Vulnerability
| Bugtraq ID: | 30500 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-3423 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2008 12:00AM |
| Updated: | Aug 01 2008 08:27PM |
| Credit: | Security Assurance Team of the National Australia Bank |
| Vulnerable: |
IBM Websphere Portal Server 6.1.0.0 IBM Websphere Portal Server 6.0.1.3 IBM Websphere Portal Server 6.0.1.1 IBM Websphere Portal Server 6.0.1.0 IBM Websphere Portal Server 6.0.0.1 IBM Websphere Portal Server 6.0.0.0 IBM Websphere Portal Server 5.1.0.5 IBM Websphere Portal Server 5.1.0.4 IBM Websphere Portal Server 5.1.0.3 IBM Websphere Portal Server 5.1.0.2 IBM Websphere Portal Server 5.1.0.1 IBM Websphere Portal Server 5.1.0.0 IBM Websphere Portal Express 6.1.0.0 IBM Websphere Portal Express 6.0.1.3 IBM Websphere Portal Express 6.0.1.1 IBM Websphere Portal Express 6.0.1.0 IBM Websphere Portal Express 6.0.0.1 IBM Websphere Portal Express 6.0.0.0 IBM Websphere Portal Express 5.1.0.5 IBM Websphere Portal Express 5.1.0.4 IBM Websphere Portal Express 5.1.0.3 IBM Websphere Portal Express 5.1.0.2 IBM Websphere Portal Express 5.1.0.1 IBM Websphere Portal Express 5.1.0.0 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Portal Server Remote Administration Authentication Bypass Vulnerability
IBM WebSphere Portal Server is prone to an authentication-bypass vulnerability.
Exploiting this issue can allow remote attackers to gain unauthorized administrative privileges.
The following versions of WebSphere Portal Server and WebSphere Portal Express are vulnerable:
5.1.0.1 to 5.1.0.5
6.0.0.0 and 6.0.0.1
6.0.1.0, 6.0.1.1, 6.0.1.3
6.1.0.0
IBM WebSphere Portal Server is prone to an authentication-bypass vulnerability.
Exploiting this issue can allow remote attackers to gain unauthorized administrative privileges.
The following versions of WebSphere Portal Server and WebSphere Portal Express are vulnerable:
5.1.0.1 to 5.1.0.5
6.0.0.0 and 6.0.0.1
6.0.1.0, 6.0.1.1, 6.0.1.3
6.1.0.0
Exploit / POC
IBM WebSphere Portal Server Remote Administration Authentication Bypass Vulnerability
Attackers will likely exploit this issue via a browser.
Attackers will likely exploit this issue via a browser.
Solution / Fix
IBM WebSphere Portal Server Remote Administration Authentication Bypass Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.
References
IBM WebSphere Portal Server Remote Administration Authentication Bypass Vulnerability
References:
References: