IBM WebSphere Application Server Arbitrary File Information Disclosure Vulnerability
BID:33533
Info
IBM WebSphere Application Server Arbitrary File Information Disclosure Vulnerability
| Bugtraq ID: | 33533 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2009 12:00AM |
| Updated: | Jan 30 2009 05:09PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Websphere Application Server 6.0.1 |
| Not Vulnerable: |
IBM Websphere Application Server 6.0.2 .33 |
Discussion
IBM WebSphere Application Server Arbitrary File Information Disclosure Vulnerability
IBM WebSphere Application Server is prone to an information-disclosure vulnerability because it retrieves arbitrary files.
Attackers can exploit this issue to obtain sensitive information that could aid in further attacks.
WebSphere Application Server 6.0.1 for z/OS is vulnerable.
IBM WebSphere Application Server is prone to an information-disclosure vulnerability because it retrieves arbitrary files.
Attackers can exploit this issue to obtain sensitive information that could aid in further attacks.
WebSphere Application Server 6.0.1 for z/OS is vulnerable.
Exploit / POC
IBM WebSphere Application Server Arbitrary File Information Disclosure Vulnerability
An attacker will likely use a browser to exploit this issue.
An attacker will likely use a browser to exploit this issue.
Solution / Fix
IBM WebSphere Application Server Arbitrary File Information Disclosure Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
IBM Websphere Application Server 6.0.1
Solution:
Vendor fixes are available. Please see the references for more information.
IBM Websphere Application Server 6.0.1
References
IBM WebSphere Application Server Arbitrary File Information Disclosure Vulnerability
References:
References: