IBM WebSphere Sensor Events Multiple Input Validation Vulnerabilities
BID:53859
Info
IBM WebSphere Sensor Events Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 53859 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2012 12:00AM |
| Updated: | Jun 29 2012 07:40AM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Sensor Events 7.0 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Sensor Events Multiple Input Validation Vulnerabilities
IBM WebSphere Sensor Events is prone to multiple input validation vulnerabilities that includes multiple cross-site scripting vulnerabilities, an unspecified security vulnerability, and a directory-traversal vulnerability.
An attacker can exploit these issues to steal cookie-based authentication credentials, perform unauthorized actions in the context of a user's session, or disclose sensitive-information.
IBM WebSphere Sensor Events is prone to multiple input validation vulnerabilities that includes multiple cross-site scripting vulnerabilities, an unspecified security vulnerability, and a directory-traversal vulnerability.
An attacker can exploit these issues to steal cookie-based authentication credentials, perform unauthorized actions in the context of a user's session, or disclose sensitive-information.
Exploit / POC
IBM WebSphere Sensor Events Multiple Input Validation Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
IBM WebSphere Sensor Events Multiple Input Validation Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM WebSphere Sensor Events Multiple Input Validation Vulnerabilities
References:
References: