IBM WebSphere Application Server Remote Information Disclosure Vulnerability
BID:12812
Info
IBM WebSphere Application Server Remote Information Disclosure Vulnerability
| Bugtraq ID: | 12812 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 15 2005 12:00AM |
| Updated: | Mar 15 2005 12:00AM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
IBM WebSphere Application Server Professional Edition 5.6 .0.1 IBM WebSphere Application Server Professional Edition 5.6 IBM WebSphere Application Server Professional Edition 5.5 IBM WebSphere Application Server Express 5.6 .0.1 IBM WebSphere Application Server Express 5.6 IBM WebSphere Application Server Express 5.5 IBM WebSphere Application Server Business Edition 5.6 .0.1 IBM WebSphere Application Server Business Edition 5.6 IBM WebSphere Application Server Business Edition 5.5 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Remote Information Disclosure Vulnerability
A remote information disclosure vulnerability affects IBM WebSphere Application Server. This issue is due to a failure of the application to properly secure potentially sensitive information, and may be triggered only under certain circumstances.
This issue will cause potentially sensitive information to be preloaded into a password change Web form, potentially facilitating brute force password attacks.
A remote information disclosure vulnerability affects IBM WebSphere Application Server. This issue is due to a failure of the application to properly secure potentially sensitive information, and may be triggered only under certain circumstances.
This issue will cause potentially sensitive information to be preloaded into a password change Web form, potentially facilitating brute force password attacks.
Exploit / POC
IBM WebSphere Application Server Remote Information Disclosure Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
IBM WebSphere Application Server Remote Information Disclosure Vulnerability
Solution:
The vendor has released a fix pack dealing with this issue.
IBM WebSphere Application Server Express 5.5
IBM WebSphere Application Server Business Edition 5.5
IBM WebSphere Application Server Professional Edition 5.5
IBM WebSphere Application Server Business Edition 5.6 .0.1
IBM WebSphere Application Server Express 5.6
IBM WebSphere Application Server Business Edition 5.6
IBM WebSphere Application Server Express 5.6 .0.1
IBM WebSphere Application Server Professional Edition 5.6 .0.1
IBM WebSphere Application Server Professional Edition 5.6
Solution:
The vendor has released a fix pack dealing with this issue.
IBM WebSphere Application Server Express 5.5
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Business Edition 5.5
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Professional Edition 5.5
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Business Edition 5.6 .0.1
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Express 5.6
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Business Edition 5.6
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Express 5.6 .0.1
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Professional Edition 5.6 .0.1
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Professional Edition 5.6
-
IBM WebSphere Commerce 5.6.0.3 Fix Pack
http://www-1.ibm.com/support/docview.wss?uid=swg24008748
References
IBM WebSphere Application Server Remote Information Disclosure Vulnerability
References:
References: