IBM WebSphere Message Broker Information Disclosure Vulnerability
BID:33819
Info
IBM WebSphere Message Broker Information Disclosure Vulnerability
| Bugtraq ID: | 33819 |
| Class: | Design Error |
| CVE: |
CVE-2009-0503 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 10 2009 12:00AM |
| Updated: | Feb 18 2009 05:07PM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Message Broker 6.1 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Message Broker Information Disclosure Vulnerability
IBM WebSphere Message Broker is prone to a local information-disclosure vulnerability caused by a design error.
Exploiting this issue may allow a local attacker to access sensitive information about database connections such as unencrypted passwords, potentially allowing them to gain unauthorized access. This may aid in further attacks.
This issue affects IBM WebSphere Message Broker 6.1.
IBM WebSphere Message Broker is prone to a local information-disclosure vulnerability caused by a design error.
Exploiting this issue may allow a local attacker to access sensitive information about database connections such as unencrypted passwords, potentially allowing them to gain unauthorized access. This may aid in further attacks.
This issue affects IBM WebSphere Message Broker 6.1.
Exploit / POC
IBM WebSphere Message Broker Information Disclosure Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
IBM WebSphere Message Broker Information Disclosure Vulnerability
Solution:
IBM has released fixes. Please see the vendor reference for details.
Solution:
IBM has released fixes. Please see the vendor reference for details.
References
IBM WebSphere Message Broker Information Disclosure Vulnerability
References:
References: