SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
Search :
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

IBM Websphere Application Server Multiple Vulnerabilities


Arrow  SecurityAlert : 910
Arrow  CVE : CVE-2006-2436
Arrow  CVE : CVE-2006-2435
Arrow  CVE : CVE-2006-2434
Arrow  CVE : CVE-2006-2433
Arrow  CVE : CVE-2006-2432
Arrow  CVE : CVE-2006-2431
Arrow  CVE : CVE-2006-2430
Arrow  CVE : CVE-2006-2429
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Given : No
Arrow  Credit : SnoB
Arrow  Published : 19.05.2006

Arrow  Affected Software : IBM Websphere Application Server 5.0.2.x and 5.1.1.x.



Arrow  Advisory Text :  

Impact: Unknown
Security Bypass
Exposure of sensitive information

Where: From remote

Solution Status: Vendor Patch

Description:
Some vulnerabilities have been reported in IBM WebSphere Application
Server, where some have unknown impacts and others may disclose sensitive
information or bypass certain security restrictions.

1) An unspecified security/integrity exposure exists in the HTTP request
handlers.

This has been reported in version 6.0.2.x.

2) User credentials may be written into the "addNode.log" file in plain
text when adding the base node into the deployment manager.

This has been reported in versions 5.0.2.x, 5.1.1.x, and 6.0.2.x.

3) An unspecified security issue affects the SOAP port.

This has been reported in versions 5.0.2.x and 6.0.2.x.

4) An unspecified vulnerability exists in the administrative console.

This has been reported in version 6.0.2.x.

5) An error in the WebSphere Common Configuration Mode and CommonArchive
and J2EE Models may cause sensitive information to be displayed in the
trace.

This has been reported in version 5.1.1.x.

6) A manipulated LTPA token from subjects credential can be exploited to
access an EJB on Solaris systems.

Successful exploitation requires that LTPA authentication is used.

This has been reported in versions 5.0.2.x and 5.1.1.x.

7) An error may cause unintended execution of scripts when inserting
certain script tags in URLs.

This has been reported in versions 5.0.2.x and 5.1.1.x.

Other issues, where some may be security-related, have also been reported.

Solution:
Apply patches.

Version 6.0.2 Fix Pack 9 (6.0.2.9):
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064

Version 5.1.1 Cumulative Fix 10 ():
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012009

Version 5.0.2 Cumulative Fix 16 (5.0.2.16):
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24011773

Provided and/or discovered by:
Reported by the vendor

Reported by SnoB

SnoBmsn[at]hotmail[dot]com
Cyber-Security | Cyber-Warrior




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

Multiple Vendors libc/gdtoa printf(3) Array Overrun

Security Risk High- 2009-05-30

SecurityReason realised new advisory about vulnerabilities libc/gdtoa...

Apache RSS Apache Alert

» Apache Tomcat
   RequestDispatcher
   directory traversal
   vulnerability

» Apache mod_dav / svn
   Remote Denial of Service
   Exploit

» Apache Tomcat Information
   disclosure

» Apache Tomcat User
   enumeration vulnerability
   with FORM authentication

PHP RSS PHP Alert

» PHP 5.2.9 curl safe_mode
   & open_basedir bypass

» PHP 5.2.6 SAPI
   php_getuid() overload

» PHP
   ZipArchive::extractTo()
   Directory Traversal
   Vulnerability

» PHP 5.2.6 dba_replace()
   destroying file

Copyright © SecurityReason.com. All Rights Reserved.