IBM WebSphere Application Server Installation Factory Information Disclosure Vulnerability
BID:33849
Info
IBM WebSphere Application Server Installation Factory Information Disclosure Vulnerability
| Bugtraq ID: | 33849 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-0437 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 09 2009 12:00AM |
| Updated: | Feb 20 2009 08:17PM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Application Server 6.0.2 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Installation Factory Information Disclosure Vulnerability
IBM WebSphere Appplication Server Installation Factory is prone to a local information-disclosure vulnerability because it logs sensitive information.
Exploiting this issue may allow a local attacker to access sensitive information that may aid in further attacks.
This issue affects IBM WebSphere Application Server 6.0.2 installed on Microsoft Windows.
IBM WebSphere Appplication Server Installation Factory is prone to a local information-disclosure vulnerability because it logs sensitive information.
Exploiting this issue may allow a local attacker to access sensitive information that may aid in further attacks.
This issue affects IBM WebSphere Application Server 6.0.2 installed on Microsoft Windows.
Exploit / POC
IBM WebSphere Application Server Installation Factory Information Disclosure Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
IBM WebSphere Application Server Installation Factory Information Disclosure Vulnerability
Solution:
IBM has released fixes. Please see the vendor reference for details.
Solution:
IBM has released fixes. Please see the vendor reference for details.
References
IBM WebSphere Application Server Installation Factory Information Disclosure Vulnerability
References:
References: