CVE-2008-4679

6.8
CVSS v2.0 Base Score
1.56%
LOW RiskEPSS (74th percentile)

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.

Published: 10/22/2008
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

1.56%LOW Exploitation Risk
74th percentile

This vulnerability has a 1.56% probability of being exploited in the next 30 days, ranking higher than 74% of all scored CVEs.

CWE Classification

Advertisement