IBM WebSphere Application Server WAR File Information Disclosure Vulnerability
BID:34104
Info
IBM WebSphere Application Server WAR File Information Disclosure Vulnerability
| Bugtraq ID: | 34104 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-0508 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2009 12:00AM |
| Updated: | Apr 28 2009 01:26PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 6.0.2 .9 IBM Websphere Application Server 6.0.2 .7 IBM Websphere Application Server 6.0.2 .5 IBM Websphere Application Server 6.0.2 .33 IBM Websphere Application Server 6.0.2 .31 IBM Websphere Application Server 6.0.2 .3 IBM Websphere Application Server 6.0.2 .29 IBM Websphere Application Server 6.0.2 .25 IBM Websphere Application Server 6.0.2 .24 IBM Websphere Application Server 6.0.2 .23 IBM Websphere Application Server 6.0.2 .22 IBM Websphere Application Server 6.0.2 .21 IBM Websphere Application Server 6.0.2 .19 IBM Websphere Application Server 6.0.2 .17 IBM Websphere Application Server 6.0.2 .15 IBM Websphere Application Server 6.0.2 .13 IBM Websphere Application Server 6.0.2 .11 IBM Websphere Application Server 6.0.2 .1 IBM Websphere Application Server 6.0.2 IBM Websphere Application Server 5.1 .0.5 IBM Websphere Application Server 5.1 .0.4 IBM Websphere Application Server 5.1 .0.3 IBM Websphere Application Server 5.1 .0.2 IBM Websphere Application Server 5.1 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.0.2.19 IBM Websphere Application Server 6.0.2 Fix Pack 17 IBM Tivoli Workload Scheduler 8.5 IBM Tivoli Workload Scheduler 8.4 IBM Tivoli Workload Scheduler 8.3 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server WAR File Information Disclosure Vulnerability
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 5.1.0, 6.0.2, 6.1, and 7.0.
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 5.1.0, 6.0.2, 6.1, and 7.0.
Exploit / POC
IBM WebSphere Application Server WAR File Information Disclosure Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
IBM WebSphere Application Server WAR File Information Disclosure Vulnerability
Solution:
IBM has released fixes. Please see the vendor reference for details.
Solution:
IBM has released fixes. Please see the vendor reference for details.
References
IBM WebSphere Application Server WAR File Information Disclosure Vulnerability
References:
References: