IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
BID:15303
Info
IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
| Bugtraq ID: | 15303 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Nov 03 2005 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Websphere Application Server 5.1.1 .4 IBM Websphere Application Server 5.1.1 .3 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
A remote information disclosure vulnerability reportedly affects the IBM WebSphere Application Server.
A malicious user may leverage this issue to disclose potentially sensitive information, aiding them in further attacks.
A remote information disclosure vulnerability reportedly affects the IBM WebSphere Application Server.
A malicious user may leverage this issue to disclose potentially sensitive information, aiding them in further attacks.
Exploit / POC
IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
Solution:
IBM has released APAR PK11017, along with a fix to address this issue. Please refer to the referenced document for further information on obtaining and installing fixes.
Solution:
IBM has released APAR PK11017, along with a fix to address this issue. Please refer to the referenced document for further information on obtaining and installing fixes.
References
IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
References:
References: