IBM WebSphere JSP Root Password Disclosure Vulnerability
BID:3682
Info
IBM WebSphere JSP Root Password Disclosure Vulnerability
| Bugtraq ID: | 3682 |
| Class: | Design Error |
| CVE: |
CVE-2001-1189 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 13 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was submitted to BugTraq on December 13th, 2001 by Heikki Tunkelo <[email protected]>. |
| Vulnerable: |
IBM Websphere Application Server 3.5.3 IBM Websphere Application Server 3.5.2 IBM Websphere Application Server 3.5.1 IBM Websphere Application Server 3.5 IBM Websphere Application Server 3.0.2 .1 IBM Websphere Application Server 3.0.2 IBM Websphere Application Server 3.0 .2.4 IBM Websphere Application Server 3.0 .2.3 IBM Websphere Application Server 3.0 .2.2 IBM Websphere Application Server 3.0 |
| Not Vulnerable: | |
Discussion
IBM WebSphere JSP Root Password Disclosure Vulnerability
IBM WebSphere is a commercial web application server which runs on a number of platforms.
The root password for AIX, Linux and Sun systems is stored plaintext in a file called $WASROOT/properties/sas.server.props, which is not readable by non-root users. However, IBM WebSphere normally runs as root in default installations. In addition, all Java code on a host running IBM WebSphere is also executed with root privileges. This leaves an opening whereby an unprivileged local attacker could create a JSP script which could read the root password from $WASROOT/properties/sas.server.props to gain elevated privileges.
There are a number of other security implications that arise from a local unprivileged user being able to execute arbitrary code as root, all resulting in an escalation of privileges. Additionally, with the default configuration, hosts running IBM WebSphere may be vulnerable to a remote root compromise in cases where a remotely exploitable vulnerability allows arbitrary code execution.
IBM WebSphere is a commercial web application server which runs on a number of platforms.
The root password for AIX, Linux and Sun systems is stored plaintext in a file called $WASROOT/properties/sas.server.props, which is not readable by non-root users. However, IBM WebSphere normally runs as root in default installations. In addition, all Java code on a host running IBM WebSphere is also executed with root privileges. This leaves an opening whereby an unprivileged local attacker could create a JSP script which could read the root password from $WASROOT/properties/sas.server.props to gain elevated privileges.
There are a number of other security implications that arise from a local unprivileged user being able to execute arbitrary code as root, all resulting in an escalation of privileges. Additionally, with the default configuration, hosts running IBM WebSphere may be vulnerable to a remote root compromise in cases where a remotely exploitable vulnerability allows arbitrary code execution.
Exploit / POC
IBM WebSphere JSP Root Password Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM WebSphere JSP Root Password Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM WebSphere JSP Root Password Disclosure Vulnerability
References:
References: