IBM WebSphere Net.Commerce Unprotected Configuration File Vulnerability
BID:2858
Info
IBM WebSphere Net.Commerce Unprotected Configuration File Vulnerability
| Bugtraq ID: | 2858 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 1999 12:00AM |
| Updated: | Apr 14 1999 12:00AM |
| Credit: | This vulnerability is detailed in full in an advisory published by IBM on April 14th, 1999. |
| Vulnerable: |
IBM Net.Commerce Hosting Server 3.1.2 IBM Net.Commerce Hosting Server 3.1.1 IBM Net.Commerce 3.1.2 IBM Net.Commerce 3.1.1 IBM Net.Commerce 3.1 IBM Net.Commerce 2.0 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Net.Commerce Unprotected Configuration File Vulnerability
IBM WebSphere is series of webserver and webserver-related products.
By default, configuration files used by WebSphere, Net.Commerce, etc. are stored without access-restriction in the document root directory of the webserver. These files will be disclosed to any user making a request for them via a web-browser.
IBM WebSphere is series of webserver and webserver-related products.
By default, configuration files used by WebSphere, Net.Commerce, etc. are stored without access-restriction in the document root directory of the webserver. These files will be disclosed to any user making a request for them via a web-browser.
Exploit / POC
IBM WebSphere Net.Commerce Unprotected Configuration File Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM WebSphere Net.Commerce Unprotected Configuration File Vulnerability
References:
References: