IBM WebSphere Application JavaServer Faces Functionality Information Disclosure Vulnerability
BID:50463
Info
IBM WebSphere Application JavaServer Faces Functionality Information Disclosure Vulnerability
| Bugtraq ID: | 50463 |
| Class: | Access Validation Error |
| CVE: |
CVE-2011-1368 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2011 12:00AM |
| Updated: | Sep 26 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
IBM Websphere Application Server 8.0.0.0 |
| Not Vulnerable: |
IBM Websphere Application Server 8.0.0.1 |
Discussion
IBM WebSphere Application JavaServer Faces Functionality Information Disclosure Vulnerability
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability that affects the JavaServer Faces (JSF) functionality.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 8.x before 8.0.0.1.
IBM WebSphere Application Server (WAS) is prone to an information-disclosure vulnerability that affects the JavaServer Faces (JSF) functionality.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects WAS 8.x before 8.0.0.1.
Exploit / POC
IBM WebSphere Application JavaServer Faces Functionality Information Disclosure Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
IBM WebSphere Application JavaServer Faces Functionality Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
IBM WebSphere Application JavaServer Faces Functionality Information Disclosure Vulnerability
References:
References: