IBM FileNet Application Engine Workplace Component Information Disclosure Vulnerability
BID:43405
Info
IBM FileNet Application Engine Workplace Component Information Disclosure Vulnerability
| Bugtraq ID: | 43405 |
| Class: | Design Error |
| CVE: |
CVE-2008-7261 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 01 2009 12:00AM |
| Updated: | Aug 01 2009 12:00AM |
| Credit: | IBM |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM FileNet Application Engine Workplace Component Information Disclosure Vulnerability
IBM FileNet Application Engine is prone to an information-disclosure vulnerability because it incorrectly
handles user credentials.
Local attackers can exploit this issue to gain access to sensitive information that may lead to further attacks.
Versions prior to IBM FileNet Application Engine 3.5.1-010 are vulnerable.
IBM FileNet Application Engine is prone to an information-disclosure vulnerability because it incorrectly
handles user credentials.
Local attackers can exploit this issue to gain access to sensitive information that may lead to further attacks.
Versions prior to IBM FileNet Application Engine 3.5.1-010 are vulnerable.
Exploit / POC
IBM FileNet Application Engine Workplace Component Information Disclosure Vulnerability
Attackers can use readily available command line tools to exploit this issue.
Attackers can use readily available command line tools to exploit this issue.
Solution / Fix
IBM FileNet Application Engine Workplace Component Information Disclosure Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
IBM FileNet Application Engine Workplace Component Information Disclosure Vulnerability
References:
References: