IBM WebSphere Application Server 'logoutExitPage' Parameter Security Bypass Vulnerability
BID:48710
Info
IBM WebSphere Application Server 'logoutExitPage' Parameter Security Bypass Vulnerability
| Bugtraq ID: | 48710 |
| Class: | Design Error |
| CVE: |
CVE-2011-1355 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2011 12:00AM |
| Updated: | Jul 16 2011 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1 |
| Not Vulnerable: |
IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 6.1.0.39 |
Discussion
IBM WebSphere Application Server 'logoutExitPage' Parameter Security Bypass Vulnerability
IBM WebSphere Application Server (WAS) is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to bypass certain security restrictions, which may lead to other attacks.
IBM WebSphere Application Server 6.1 and 7.0 are vulnerable; other versions may also be affected.
IBM WebSphere Application Server (WAS) is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to bypass certain security restrictions, which may lead to other attacks.
IBM WebSphere Application Server 6.1 and 7.0 are vulnerable; other versions may also be affected.
Solution / Fix
IBM WebSphere Application Server 'logoutExitPage' Parameter Security Bypass Vulnerability
Solution:
The vendor has released a fix. Please see the references for details.
Solution:
The vendor has released a fix. Please see the references for details.