VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-10-29 12:00
Updated : 2018-10-10 13:05
NVD link : CVE-2010-3700
Mitre link : CVE-2010-3700
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
acegisecurity
- acegi-security
ibm
- websphere_application_server
vmware
- springsource_spring_security