首页 -> 安全研究

安全研究

安全漏洞
IBM WebSphere Application Server远程信息泄露漏洞

发布日期:2005-03-17
更新日期:2005-03-17

受影响系统:
IBM Websphere Application Server Professional Edition 5.6.0.1
IBM Websphere Application Server Professional Edition 5.6
IBM Websphere Application Server Professional Edition 5.5
IBM Websphere Application Server Express 5.6.0.1
IBM Websphere Application Server Express 5.6
IBM Websphere Application Server Express 5.5
IBM Websphere Application Server Business Edition 5.6.0.1
IBM Websphere Application Server Business Edition 5.6
IBM Websphere Application Server Business Edition 5.5
描述:
BUGTRAQ  ID: 12812

IBM Websphere应用服务器以基于Java和Servlet引擎为基础,支持多种HTTP服务,可帮助用户完成从开发、发布到维护交互式的动态网站的所有工作。

IBM WebSphere Application Serve中存在一个远程信息泄漏漏洞,可能导致网络敏感信息泄露。

漏洞的起因是应用程序在某些环境中不能正确的处理敏感信息,导致预先在口令更改Web表单中加载敏感信息,这可能方便攻击者的暴力猜测口令攻击。

<*来源:IBM (ncsupp@ca.ibm.com
  
  链接:http://www-306.ibm.com/software/genservers/commerce/servers/2001-2.htm
*>

建议:
厂商补丁:

IBM
---
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

IBM WebSphere Application Server Business Edition 5.5:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Professional Edition 5.5:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Express 5.5:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Professional Edition 5.6 .0.1:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Business Edition 5.6 .0.1:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Express 5.6 .0.1:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Express 5.6:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Business Edition 5.6:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748
IBM WebSphere Application Server Professional Edition 5.6:
      IBM Patch WebSphere Commerce 5.6.0.3 Fix Pack
      http://www-1.ibm.com/support/docview.wss?uid=swg24008748

浏览次数:3317
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障