IBM WebSphere Application Server CVE-2014-3022 Unspecified Information Disclosure Vulnerability
BID:68211
Info
IBM WebSphere Application Server CVE-2014-3022 Unspecified Information Disclosure Vulnerability
| Bugtraq ID: | 68211 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3022 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2014 12:00AM |
| Updated: | Aug 21 2014 12:23AM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 21 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .13 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.6 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.4 IBM Websphere Application Server 7.0.0.23 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server CVE-2014-3022 Unspecified Information Disclosure Vulnerability
The IBM WebSphere Application Server is prone to an unspecified remote information-disclosure vulnerability because of improper handling of SOAP responses.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
The following versions are vulnerable:
IBM WebSphere Application Server 8.5.0.0 through 8.5.5.2
IBM WebSphere Application Server 8.0.0.0 through 8.0.0.8
IBM WebSphere Application Server 7.0.0.0 through 7.0.0.31
The IBM WebSphere Application Server is prone to an unspecified remote information-disclosure vulnerability because of improper handling of SOAP responses.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
The following versions are vulnerable:
IBM WebSphere Application Server 8.5.0.0 through 8.5.5.2
IBM WebSphere Application Server 8.0.0.0 through 8.0.0.8
IBM WebSphere Application Server 7.0.0.0 through 7.0.0.31
Exploit / POC
IBM WebSphere Application Server CVE-2014-3022 Unspecified Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
IBM WebSphere Application Server CVE-2014-3022 Unspecified Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM WebSphere Application Server CVE-2014-3022 Unspecified Information Disclosure Vulnerability
References:
References: