IBM WebSphere Application Server serveServletsByClassnameEnabled Info Disclosure Vulnerability
BID:27371
Info
IBM WebSphere Application Server serveServletsByClassnameEnabled Info Disclosure Vulnerability
| Bugtraq ID: | 27371 |
| Class: | Configuration Error |
| CVE: |
CVE-2008-0389 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2008 12:00AM |
| Updated: | Apr 09 2008 03:38AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 6.0.2 .9 IBM Websphere Application Server 6.0.2 .7 IBM Websphere Application Server 6.0.2 .5 IBM Websphere Application Server 6.0.2 .3 IBM Websphere Application Server 6.0.2 .25 IBM Websphere Application Server 6.0.2 .24 IBM Websphere Application Server 6.0.2 .23 IBM Websphere Application Server 6.0.2 .22 IBM Websphere Application Server 6.0.2 .21 IBM Websphere Application Server 6.0.2 .19 IBM Websphere Application Server 6.0.2 .17 IBM Websphere Application Server 6.0.2 .15 IBM Websphere Application Server 6.0.2 .13 IBM Websphere Application Server 6.0.2 .11 IBM Websphere Application Server 6.0.2 .1 IBM Websphere Application Server 6.0.2 IBM Websphere Application Server 6.0.1 IBM Websphere Application Server 6.0 IBM Websphere Application Server 5.1.1 .9 IBM Websphere Application Server 5.1.1 .8 IBM Websphere Application Server 5.1.1 .7 IBM Websphere Application Server 5.1.1 .6 IBM Websphere Application Server 5.1.1 .5 IBM Websphere Application Server 5.1.1 .4 IBM Websphere Application Server 5.1.1 .3 IBM Websphere Application Server 5.1.1 .2 IBM Websphere Application Server 5.1.1 .15 IBM Websphere Application Server 5.1.1 .14 IBM Websphere Application Server 5.1.1 .13 IBM Websphere Application Server 5.1.1 .12 IBM Websphere Application Server 5.1.1 .11 IBM Websphere Application Server 5.1.1 .10 IBM Websphere Application Server 5.1.1 .1 IBM Websphere Application Server 5.1.1 IBM Websphere Application Server 6.0.2.19 IBM Websphere Application Server 6.0.2 Fix Pack 17 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server serveServletsByClassnameEnabled Info Disclosure Vulnerability
IBM WebSphere Application Server is prone to vulnerability because of a default setting that can allow attackers to obtain potentially sensitive information.
Information harvested could aid attackers in further exploits.
WebSphere Application Server 6.0 through 6.0.2.25 and 6.1 through 6.1.0.14 are vulnerable.
IBM WebSphere Application Server is prone to vulnerability because of a default setting that can allow attackers to obtain potentially sensitive information.
Information harvested could aid attackers in further exploits.
WebSphere Application Server 6.0 through 6.0.2.25 and 6.1 through 6.1.0.14 are vulnerable.
Exploit / POC
IBM WebSphere Application Server serveServletsByClassnameEnabled Info Disclosure Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
IBM WebSphere Application Server serveServletsByClassnameEnabled Info Disclosure Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
IBM Websphere Application Server 6.0
IBM Websphere Application Server 6.0.1
IBM Websphere Application Server 6.0.2 .25
IBM Websphere Application Server 6.0.2
IBM Websphere Application Server 6.0.2 .9
IBM Websphere Application Server 6.0.2 .5
IBM Websphere Application Server 6.1
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
IBM Websphere Application Server 6.0
-
IBM 6.0.0.0-WS-WAS-IFPK52059.pak
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PK 52059/6.0.0.0-WS-WAS-IFPK52059.pak
IBM Websphere Application Server 6.0.1
-
IBM 6.0.1.0-WS-WAS-IFPK52059.pak
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PK 52059/6.0.1.0-WS-WAS-IFPK52059.pak
IBM Websphere Application Server 6.0.2 .25
-
IBM 6.0.2.25-WS-WAS-IFPK52059.pak
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PK 52059/6.0.2.25-WS-WAS-IFPK52059.pak
IBM Websphere Application Server 6.0.2
-
IBM 6.0.2.0-WS-WAS-IFPK52059.pak
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PK 52059/6.0.2.0-WS-WAS-IFPK52059.pak
IBM Websphere Application Server 6.0.2 .9
-
IBM 6.0.2.9-WS-WAS-IFPK52059.pak
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PK 52059/6.0.2.9-WS-WAS-IFPK52059.pak
IBM Websphere Application Server 6.0.2 .5
-
IBM 6.0.2.5-WS-WAS-IFPK52059.pak
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PK 52059/6.0.2.5-WS-WAS-IFPK52059.pak
IBM Websphere Application Server 6.1
-
IBM 6.1.0.0-WS-WAS-IFPK52059.pak
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PK 52059/6.1.0.0-WS-WAS-IFPK52059.pak
References
IBM WebSphere Application Server serveServletsByClassnameEnabled Info Disclosure Vulnerability
References:
References: