IBM WebSphere Application Server Closed Connection Information Disclosure Vulnerability
BID:24608
Info
IBM WebSphere Application Server Closed Connection Information Disclosure Vulnerability
| Bugtraq ID: | 24608 |
| Class: | Design Error |
| CVE: |
CVE-2007-3397 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | This issue was reported by IBM. |
| Vulnerable: |
IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 6.0.2 .9 IBM Websphere Application Server 6.0.2 .7 IBM Websphere Application Server 6.0.2 .5 IBM Websphere Application Server 6.0.2 .3 IBM Websphere Application Server 6.0.2 .15 IBM Websphere Application Server 6.0.2 .13 IBM Websphere Application Server 6.0.2 .11 IBM Websphere Application Server 6.0.2 .1 IBM Websphere Application Server 6.0.2 IBM Websphere Application Server 6.0 IBM Websphere Application Server 6.0.2.19 IBM Websphere Application Server 6.0.2 Fix Pack 17 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Closed Connection Information Disclosure Vulnerability
IBM WebSphere Application Server is prone to an information-disclosure vulnerability. An attacker can exploit this issue by prematurely closing an active connection to the server and subsequently making another request.
Exploiting this issue allows remote attackers to potentially access the contents of a previous 'webcontainer' buffer, aiding them in further attacks.
IBM WebSphere Application Server is prone to an information-disclosure vulnerability. An attacker can exploit this issue by prematurely closing an active connection to the server and subsequently making another request.
Exploiting this issue allows remote attackers to potentially access the contents of a previous 'webcontainer' buffer, aiding them in further attacks.
Exploit / POC
IBM WebSphere Application Server Closed Connection Information Disclosure Vulnerability
Attackers can use client software (such as a browser) to exploit this issue.
Attackers can use client software (such as a browser) to exploit this issue.
Solution / Fix
IBM WebSphere Application Server Closed Connection Information Disclosure Vulnerability
Solution:
IBM has released a patch and an advisory to address this issue. Please see the referenced advisory for information on obtaining fixes. A permanent fix is scheduled for fixpacks 6.0.2.21 and 6.1.0.9.
Solution:
IBM has released a patch and an advisory to address this issue. Please see the referenced advisory for information on obtaining fixes. A permanent fix is scheduled for fixpacks 6.0.2.21 and 6.1.0.9.
References
IBM WebSphere Application Server Closed Connection Information Disclosure Vulnerability
References:
References: