IBM WebSphere Application Server Feature Pack for CEA Spoofing Vulnerability
BID:37392
Info
IBM WebSphere Application Server Feature Pack for CEA Spoofing Vulnerability
| Bugtraq ID: | 37392 |
| Class: | Unknown |
| CVE: |
CVE-2009-2749 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2009 12:00AM |
| Updated: | Dec 17 2009 11:13PM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Application Server Feature Pack for CEA 1.0 |
| Not Vulnerable: |
IBM Websphere Application Server Feature Pack for CEA 1.0 .1 |
Discussion
IBM WebSphere Application Server Feature Pack for CEA Spoofing Vulnerability
IBM WebSphere Application Server (WAS) Feature Pack for Communications Enabled Applications (CEA) is prone to a spoofing vulnerability.
An attacker can exploit this issue with man-in-the-middle techniques to spoof a collaboration session.
Versions prior to Feature Pack 1.0.0.1 on WAS 7.0.0.7 are vulnerable.
IBM WebSphere Application Server (WAS) Feature Pack for Communications Enabled Applications (CEA) is prone to a spoofing vulnerability.
An attacker can exploit this issue with man-in-the-middle techniques to spoof a collaboration session.
Versions prior to Feature Pack 1.0.0.1 on WAS 7.0.0.7 are vulnerable.
Exploit / POC
IBM WebSphere Application Server Feature Pack for CEA Spoofing Vulnerability
Attackers perform a man-in-the-middle attack to exploit this issue.
Attackers perform a man-in-the-middle attack to exploit this issue.
Solution / Fix
IBM WebSphere Application Server Feature Pack for CEA Spoofing Vulnerability
Solution:
Fixes are available. Please see the references for details.
Solution:
Fixes are available. Please see the references for details.
References
IBM WebSphere Application Server Feature Pack for CEA Spoofing Vulnerability
References:
References: