IBM WebSphere Application Server Administrative Console Buffer Overflow Vulnerability
BID:13853
Info
IBM WebSphere Application Server Administrative Console Buffer Overflow Vulnerability
| Bugtraq ID: | 13853 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2005 12:00AM |
| Updated: | Jun 03 2005 12:00AM |
| Credit: | This vulnerability was discovered and researched by Esteban Martínez Fayó of Argeniss for Application Security Inc. |
| Vulnerable: |
IBM Websphere Application Server 5.0.2 .9 IBM Websphere Application Server 5.0.2 .8 IBM Websphere Application Server 5.0.2 .7 IBM Websphere Application Server 5.0.2 .6 IBM Websphere Application Server 5.0.2 .5 IBM Websphere Application Server 5.0.2 .4 IBM Websphere Application Server 5.0.2 .3 IBM Websphere Application Server 5.0.2 .2 IBM Websphere Application Server 5.0.2 .10 IBM Websphere Application Server 5.0.2 .1 IBM Websphere Application Server 5.0.2 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Administrative Console Buffer Overflow Vulnerability
IBM WebSphere Application Server Administrative Console is prone to a buffer overflow vulnerability. This issue is due to a failure of the application in the authentication mechanism.
An attacker may exploit this issue to execute arbitrary code with the privileges of the server process. This may facilitate privilege escalation.
It should be noted this vulnerability can not be exploited if the 'global security option' is disabled.
IBM WebSphere Application Server Administrative Console is prone to a buffer overflow vulnerability. This issue is due to a failure of the application in the authentication mechanism.
An attacker may exploit this issue to execute arbitrary code with the privileges of the server process. This may facilitate privilege escalation.
It should be noted this vulnerability can not be exploited if the 'global security option' is disabled.
Exploit / POC
IBM WebSphere Application Server Administrative Console Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM WebSphere Application Server Administrative Console Buffer Overflow Vulnerability
Solution:
The vendor has addressed this issue in IBM WebSphere Application Server version 5.0.2 Cumulative Fix 11:
IBM Websphere Application Server 5.0.2
IBM Websphere Application Server 5.0.2 .8
IBM Websphere Application Server 5.0.2 .3
IBM Websphere Application Server 5.0.2 .5
IBM Websphere Application Server 5.0.2 .9
IBM Websphere Application Server 5.0.2 .2
IBM Websphere Application Server 5.0.2 .6
IBM Websphere Application Server 5.0.2 .1
IBM Websphere Application Server 5.0.2 .7
IBM Websphere Application Server 5.0.2 .4
IBM Websphere Application Server 5.0.2 .10
Solution:
The vendor has addressed this issue in IBM WebSphere Application Server version 5.0.2 Cumulative Fix 11:
IBM Websphere Application Server 5.0.2
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .8
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .3
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .5
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .9
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .2
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .6
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .1
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .7
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .4
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
IBM Websphere Application Server 5.0.2 .10
-
IBM WebSphere Application Server Cumulative Fix 11 (5.0.2.11)
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
References
IBM WebSphere Application Server Administrative Console Buffer Overflow Vulnerability
References:
References:
- Buffer overflow in WebSphere Application Server Administrative Console (Application Security, Inc.)
- WebSphere Product Page (IBM)
- Remote Buffer overflow in WebSphere Application Server Administrative Console (Team SHATTER
)