IBM WebSphere Application Server for z/OS Multiple Security Vulnerabilities
BID:55678
Info
IBM WebSphere Application Server for z/OS Multiple Security Vulnerabilities
| Bugtraq ID: | 55678 |
| Class: | Unknown |
| CVE: |
CVE-2012-3304 CVE-2012-3305 CVE-2012-3306 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2012 12:00AM |
| Updated: | Sep 24 2012 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
IBM WebSphere Application Server for z/OS 6.1 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server for z/OS Multiple Security Vulnerabilities
IBM WebSphere Application Server for z/OS is prone to the following security vulnerabilities:
1. A session-hijacking vulnerability.
2. A directory traversal vulnerability.
3. A security-bypass vulnerability.
Exploiting these issues will allow an attacker to hijack a victim's session, overwrite arbitrary local files within the context of the web server and bypass certain security restrictions. Information harvested may aid in launching further attacks.
IBM WebSphere Application Server 6.1, 7, 8 and 8.5 are vulnerable.
IBM WebSphere Application Server for z/OS is prone to the following security vulnerabilities:
1. A session-hijacking vulnerability.
2. A directory traversal vulnerability.
3. A security-bypass vulnerability.
Exploiting these issues will allow an attacker to hijack a victim's session, overwrite arbitrary local files within the context of the web server and bypass certain security restrictions. Information harvested may aid in launching further attacks.
IBM WebSphere Application Server 6.1, 7, 8 and 8.5 are vulnerable.
Exploit / POC
IBM WebSphere Application Server for z/OS Multiple Security Vulnerabilities
An attacker can exploit these issues with a web browser.
An attacker can exploit these issues with a web browser.
Solution / Fix
IBM WebSphere Application Server for z/OS Multiple Security Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
IBM WebSphere Application Server for z/OS Multiple Security Vulnerabilities
References:
References: