IBM WebSphere Application Server Long Filename Information Disclosure Vulnerability
BID:40277
Info
IBM WebSphere Application Server Long Filename Information Disclosure Vulnerability
| Bugtraq ID: | 40277 |
| Class: | Unknown |
| CVE: |
CVE-2010-0777 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2010 12:00AM |
| Updated: | May 20 2010 05:02PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 6.1.2 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 6.0.2 .9 IBM Websphere Application Server 6.0.2 .7 IBM Websphere Application Server 6.0.2 .5 IBM Websphere Application Server 6.0.2 .39 IBM Websphere Application Server 6.0.2 .35 IBM Websphere Application Server 6.0.2 .33 IBM Websphere Application Server 6.0.2 .31 IBM Websphere Application Server 6.0.2 .3 IBM Websphere Application Server 6.0.2 .29 IBM Websphere Application Server 6.0.2 .27 IBM Websphere Application Server 6.0.2 .25 IBM Websphere Application Server 6.0.2 .24 IBM Websphere Application Server 6.0.2 .23 IBM Websphere Application Server 6.0.2 .22 IBM Websphere Application Server 6.0.2 .21 IBM Websphere Application Server 6.0.2 .17 IBM Websphere Application Server 6.0.2 .15 IBM Websphere Application Server 6.0.2 .13 IBM Websphere Application Server 6.0.2 .11 IBM Websphere Application Server 6.0.2 .1 IBM Websphere Application Server 6.0.2 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM Websphere Application Server 6.0.2.41 IBM Websphere Application Server 6.0.2.19 IBM Websphere Application Server 6.0.2 Fix Pack 17 |
| Not Vulnerable: |
IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.0.2.43 |
Discussion
IBM WebSphere Application Server Long Filename Information Disclosure Vulnerability
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 6.0, 6.1, and 7.0.
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 6.0, 6.1, and 7.0.
Exploit / POC
IBM WebSphere Application Server Long Filename Information Disclosure Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
IBM WebSphere Application Server Long Filename Information Disclosure Vulnerability
Solution:
IBM has released fixes. Please see the vendor reference for details.
Solution:
IBM has released fixes. Please see the vendor reference for details.
References
IBM WebSphere Application Server Long Filename Information Disclosure Vulnerability
References:
References: