Title: IBM WebSphere Application Server (WAS) Snoop Servlet Request Handling Information Disclosure
Info
Disclosure
May 29, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
May 29, 2012
Description
IBM WebSphere Application Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by the snoop servlet missing certain access controls, which will disclose request and client information to a remote attacker when handling requests.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 6.1.0.45, 7.0.0.23 or 8.0.0.4 or higher, as they have been reported to fix this vulnerability. In addition, IBM has released a patch for some older versions.