IBM WebSphere Application Server CVE-2014-0823 Arbitrary File Disclosure Vulnerability
BID:67329
Info
IBM WebSphere Application Server CVE-2014-0823 Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 67329 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0823 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2014 12:00AM |
| Updated: | Jun 26 2014 03:34PM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Portal 6.1 IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 8.0 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server CVE-2014-0823 Arbitrary File Disclosure Vulnerability
IBM WebSphere Application Server is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to download arbitrary files in the context of the web server process, which may aid in further attacks.
IBM WebSphere Application Server prior to 8.0.0.9 and 8.5.5.2 are vulnerable.
IBM WebSphere Application Server is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to download arbitrary files in the context of the web server process, which may aid in further attacks.
IBM WebSphere Application Server prior to 8.0.0.9 and 8.5.5.2 are vulnerable.
Exploit / POC
IBM WebSphere Application Server CVE-2014-0823 Arbitrary File Disclosure Vulnerability
Attackers can exploit this issue with a browser.
Attackers can exploit this issue with a browser.
Solution / Fix
IBM WebSphere Application Server CVE-2014-0823 Arbitrary File Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM WebSphere Application Server CVE-2014-0823 Arbitrary File Disclosure Vulnerability
References:
References:
- IBM Homepage (IBM)