Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
BID:46974
Info
Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
| Bugtraq ID: | 46974 |
| Class: | Design Error |
| CVE: |
CVE-2011-1498 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2011 12:00AM |
| Updated: | Apr 13 2015 10:10PM |
| Credit: | Oleg Kalnichevski |
| Vulnerable: |
IBM Websphere Portal 8.0 Apache HttpComponents HttpClient 4.1 |
| Not Vulnerable: |
IBM Websphere Portal 8.0.0.1 CF13 Apache HttpComponents HttpClient 4.1.1 |
Discussion
Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
Apache HttpComponents is prone to an information-disclosure vulnerability that may expose users' passwords. The issue occurs in the 'HttpClient' component.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
HttpClient 4.1 is vulnerable; other versions may also be affected.
Apache HttpComponents is prone to an information-disclosure vulnerability that may expose users' passwords. The issue occurs in the 'HttpClient' component.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
HttpClient 4.1 is vulnerable; other versions may also be affected.
Solution / Fix
Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
References:
References: