IBM WebSphere Application Server WebContainer HTTP Request Header Security Weakness
BID:26457
Info
IBM WebSphere Application Server WebContainer HTTP Request Header Security Weakness
| Bugtraq ID: | 26457 |
| Class: | Design Error |
| CVE: |
CVE-2007-5944 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2007 12:00AM |
| Updated: | Mar 13 2008 03:21PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Websphere Application Server 5.1.1 .9 IBM Websphere Application Server 5.1.1 .8 IBM Websphere Application Server 5.1.1 .7 IBM Websphere Application Server 5.1.1 .6 IBM Websphere Application Server 5.1.1 .5 IBM Websphere Application Server 5.1.1 .4 IBM Websphere Application Server 5.1.1 .16 IBM Websphere Application Server 5.1.1 .15 IBM Websphere Application Server 5.1.1 .14 IBM Websphere Application Server 5.1.1 .13 IBM Websphere Application Server 5.1.1 .12 IBM Websphere Application Server 5.1.1 .11 IBM Websphere Application Server 5.1.1 .10 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server WebContainer HTTP Request Header Security Weakness
IBM WebSphere Application Server is prone to a security weakness regarding an HTTP request header. The software fails to sanitize a certain HTTP header when the data is redirected to an error message.
An attacker may exploit this issue to steal cookie-based authentication credentials and launch other attacks.
IBM WebSphere Application Server is prone to a security weakness regarding an HTTP request header. The software fails to sanitize a certain HTTP header when the data is redirected to an error message.
An attacker may exploit this issue to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
IBM WebSphere Application Server WebContainer HTTP Request Header Security Weakness
Attackers can use Flash to exploit this issue.
The following proof-of-concept code was released for a similar weakness covered in BID 19661 (Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness). The code has not been tested against IBM WebSphere Application Server but will likely work to demonstrate the issue.
Attackers can use Flash to exploit this issue.
The following proof-of-concept code was released for a similar weakness covered in BID 19661 (Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness). The code has not been tested against IBM WebSphere Application Server but will likely work to demonstrate the issue.
Solution / Fix
IBM WebSphere Application Server WebContainer HTTP Request Header Security Weakness
Solution:
The vendor has released an advisory and acpatch to address this issue. Please see the references for more information.
IBM Websphere Application Server 5.1.1 .16
Solution:
The vendor has released an advisory and acpatch to address this issue. Please see the references for more information.
IBM Websphere Application Server 5.1.1 .16
References
IBM WebSphere Application Server WebContainer HTTP Request Header Security Weakness
References:
References: