IBM WebSphere Application Server Multiple Vulnerabilities
BID:17919
Info
IBM WebSphere Application Server Multiple Vulnerabilities
| Bugtraq ID: | 17919 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2006 12:00AM |
| Updated: | Dec 18 2007 08:03PM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
IBM Websphere Application Server 6.0.2 IBM Websphere Application Server 5.1.1 .9 IBM Websphere Application Server 5.1.1 .8 IBM Websphere Application Server 5.1.1 .7 IBM Websphere Application Server 5.1.1 .6 IBM Websphere Application Server 5.1.1 .5 IBM Websphere Application Server 5.1.1 .4 IBM Websphere Application Server 5.1.1 .3 IBM Websphere Application Server 5.1.1 .2 IBM Websphere Application Server 5.1.1 .11 IBM Websphere Application Server 5.1.1 .1 IBM Websphere Application Server 5.1.1 IBM Websphere Application Server 5.0.2 .9 IBM Websphere Application Server 5.0.2 .8 IBM Websphere Application Server 5.0.2 .7 IBM Websphere Application Server 5.0.2 .6 IBM Websphere Application Server 5.0.2 .5 IBM Websphere Application Server 5.0.2 .4 IBM Websphere Application Server 5.0.2 .3 IBM Websphere Application Server 5.0.2 .2 IBM Websphere Application Server 5.0.2 .15 IBM Websphere Application Server 5.0.2 .14 IBM Websphere Application Server 5.0.2 .13 IBM Websphere Application Server 5.0.2 .12 IBM Websphere Application Server 5.0.2 .11 IBM Websphere Application Server 5.0.2 .10 IBM Websphere Application Server 5.0.2 .1 IBM Websphere Application Server 5.0.2 |
| Not Vulnerable: |
IBM Websphere Application Server 6.0.2 .9 IBM Websphere Application Server 5.1.1 .12 IBM Websphere Application Server 5.0.2 .16 |
Discussion
IBM WebSphere Application Server Multiple Vulnerabilities
IBM WebSphere Application Server is prone to multiple vulnerabilities.
These issues include vulnerabilities of unknown impact, information-disclosure vulnerabilities, and security-bypass vulnerabilities.
Other potentially security-related issues were also addressed.
Information regarding CVE-2006-2431 has been removed. This issue is discussed in detail in BID 21018 (IBM WebSphere Faultactor Cross-Site Scripting Vulnerability).
IBM WebSphere Application Server is prone to multiple vulnerabilities.
These issues include vulnerabilities of unknown impact, information-disclosure vulnerabilities, and security-bypass vulnerabilities.
Other potentially security-related issues were also addressed.
Information regarding CVE-2006-2431 has been removed. This issue is discussed in detail in BID 21018 (IBM WebSphere Faultactor Cross-Site Scripting Vulnerability).
Exploit / POC
IBM WebSphere Application Server Multiple Vulnerabilities
Some of these issues may be exploitable through a browser; other issues will require working exploits.
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may be exploitable through a browser; other issues will require working exploits.
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM WebSphere Application Server Multiple Vulnerabilities
Solution:
The vendor has released updated versions to address these issues. Contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor has released updated versions to address these issues. Contact the vendor for details on obtaining the appropriate updates.
References
IBM WebSphere Application Server Multiple Vulnerabilities
References:
References:
- 5.0.2.16: WebSphere Application Server 5.0.2 Cumulative Fix 16 for AIX (IBM)
- 5.1.1.10: WebSphere Application Server V5.1.1 Cumulative Fix 10 for AIX (IBM)
- 6.0.2.9: WebSphere Application Server V6.0.2 Fix Pack 9 for AIX platforms (IBM)
- IBM WebSphere Application Server Product Page (IBM)
- NISCC Vulnerability Advisory 756460/NISCC/WEBSPHERE (NISCC)
- IBM Websphere Application Server Multiple Vulnerabilities ([email protected])