CVE-2010-3186: IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Servic
infovulnerability
security
Summary
IBM WebSphere Application Server (WAS) versions 7.x before 7.0.0.13 and the Web Services Feature Pack versions 6.1.0.9 through 6.1.0.32 have a vulnerability in how they handle the IncludeTimestamp setting in WS-Security policy (a security standard for web services) when JAX-WS applications are used. This vulnerability can be exploited remotely, though the exact impact is not specified.
Vulnerability Details
CVSS Score
10
EPSS (30-day exploit probability)
EPSS: 1.4%
Classification
Attack SophisticationModerate
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2010-3186
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%