IBM WebSphere Application Server Administration Console Information Disclosure Vulnerability
BID:49362
Info
IBM WebSphere Application Server Administration Console Information Disclosure Vulnerability
| Bugtraq ID: | 49362 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1359 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2011 12:00AM |
| Updated: | Mar 19 2015 09:30AM |
| Credit: | Javier Castro, sxkeebler and r@b13$ of Digital Defense, Inc. |
| Vulnerable: |
IBM Websphere Application Server 7.0 .13 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1 .33 IBM Websphere Application Server 6.1 .32 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 IBM Websphere Application Server 6.1.1.0 IBM Websphere Application Server 6.1.0.39 IBM Websphere Application Server 6.1.0.35 IBM Websphere Application Server 6.1.0.34 IBM Websphere Application Server 6.1.0.33 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Administration Console Information Disclosure Vulnerability
The IBM WebSphere Application Server is prone to a remote information-disclosure vulnerability that affects the 'help' servlet of the administration console.
Remote attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
The following versions are vulnerable:
IBM WebSphere Application Server 6.1.0.0 through 6.1.0.39
IBM WebSphere Application Server 7.0.0.0 through 7.0.0.18
IBM WebSphere Application Server 8.0.0.0
The IBM WebSphere Application Server is prone to a remote information-disclosure vulnerability that affects the 'help' servlet of the administration console.
Remote attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
The following versions are vulnerable:
IBM WebSphere Application Server 6.1.0.0 through 6.1.0.39
IBM WebSphere Application Server 7.0.0.0 through 7.0.0.18
IBM WebSphere Application Server 8.0.0.0
Exploit / POC
IBM WebSphere Application Server Administration Console Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
IBM WebSphere Application Server Administration Console Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM WebSphere Application Server Administration Console Information Disclosure Vulnerability
References:
References:
- IBM Homepage (IBM)
- IBM WebSphere Application Server Product Page (IBM)
- Vulnerability Disclosure: IBM WebSphere Application Server 'help' Servlet Plug-i (Digital Defense Vulnerability Research )
- Potential security exposure with IBM WebSphere Application Server Administrative (IBM)