OSVDB ID: 82477

Title: IBM WebSphere Application Server (WAS) Snoop Servlet Request Handling Information Disclosure

Info

Disclosure

May 29, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

May 29, 2012

Description

IBM WebSphere Application Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by the snoop servlet missing certain access controls, which will disclose request and client information to a remote attacker when handling requests.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Solution: Patch / RCS, Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 6.1.0.45, 7.0.0.23 or 8.0.0.4 or higher, as they have been reported to fix this vulnerability. In addition, IBM has released a patch for some older versions.

Products

IBM Corporation

WebSphere Application Server

8.0
7.0
6.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/82477