OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA20032] IBM Websphere Application Server Multiple Vulnerabilities

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Tue May 09 2006 - 06:02:04 CDT


TITLE:
IBM Websphere Application Server Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA20032

VERIFY ADVISORY:
http://secunia.com/advisories/20032/

CRITICAL:
Moderately critical

IMPACT:
Unknown, Security Bypass, Exposure of sensitive information

WHERE:
From remote

SOFTWARE:
IBM WebSphere Application Server 6.x
http://secunia.com/product/4651/
IBM WebSphere Application Server 5.x
http://secunia.com/product/2614/

DESCRIPTION:
Some vulnerabilities have been reported in IBM WebSphere Application
Server, where some have unknown impacts and others may disclose
sensitive information or bypass certain security restrictions.

1) An unspecified security/integrity exposure exists in the HTTP
request handlers.

This has been reported in version 6.0.2.x.

2) User credentials may be written into the "addNode.log" file in
plain text when adding the base node into the deployment manager.

This has been reported in versions 5.0.2.x, 5.1.1.x, and 6.0.2.x.

3) An unspecified security issue affects the SOAP port.

This has been reported in versions 5.0.2.x and 6.0.2.x.

4) An unspecified vulnerability exists in the administrative
console.

This has been reported in version 6.0.2.x.

5) An error in the WebSphere Common Configuration Mode and
CommonArchive and J2EE Models may cause sensitive information to be
displayed in the trace.

This has been reported in version 5.1.1.x.

6) A manipulated LTPA token from subjects credential can be exploited
to access an EJB on Solaris systems.

Successful exploitation requires that LTPA authentication is used.

This has been reported in versions 5.0.2.x and 5.1.1.x.

7) An error may cause unintended execution of scripts when inserting
certain script tags in URLs.

This has been reported in versions 5.0.2.x and 5.1.1.x.

Other issues, where some may be security-related, have also been
reported.

SOLUTION:
Apply patches.

Version 6.0.2 Fix Pack 9 (6.0.2.9):
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064

Version 5.1.1 Cumulative Fix 10 ():
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012009

Version 5.0.2 Cumulative Fix 16 (5.0.2.16):
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24011773

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------