IBM WebSphere Application Server Cluster Configuration File Information Disclosure Vulnerability
BID:33905
Info
IBM WebSphere Application Server Cluster Configuration File Information Disclosure Vulnerability
| Bugtraq ID: | 33905 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-0507 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 25 2009 12:00AM |
| Updated: | Feb 25 2009 07:17PM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Application Server 6.1.2 IBM Websphere Application Server 6.2 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Cluster Configuration File Information Disclosure Vulnerability
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability because it fails to properly conceal sensitive configuration data.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 6.1.2 and 6.2.
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability because it fails to properly conceal sensitive configuration data.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 6.1.2 and 6.2.
Exploit / POC
IBM WebSphere Application Server Cluster Configuration File Information Disclosure Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
IBM WebSphere Application Server Cluster Configuration File Information Disclosure Vulnerability
Solution:
IBM has released fixes. Please see the vendor reference for details.
Solution:
IBM has released fixes. Please see the vendor reference for details.
References
IBM WebSphere Application Server Cluster Configuration File Information Disclosure Vulnerability
References:
References: