漏洞信息详情
IBM WebSphere Application Server权限许可和访问控制漏洞
漏洞简介
IBM WebSphere Application Server是一个完善的、开放的Web应用服务器,它是IBM电子商务应用架构的核心。
z/OS上运行的IBM WebSphere Application Server (WAS)存在漏洞,攻击者可读取与BBOWWPFx job和zPMT配置文件创建相关的default_create.log文件,从而获取敏感信息。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939
http://www-01.ibm.com/support/docview.wss?uid=swg1PM08892
http://www-01.ibm.com/support/docview.wss?uid=swg1PM10270
http://www-01.ibm.com/support/docview.wss?uid=swg1PM10684
http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829
http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830
参考网址
来源: VUPEN
名称: ADV-2010-1411
链接:http://www.vupen.com/english/advisories/2010/1411
来源: AIXAPAR
名称: PM15830
链接:http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830
来源: AIXAPAR
名称: PM10454
链接:http://www-01.ibm.com/support/docview.wss?uid=swg1PM10454
来源: SECUNIA
名称: 40096
链接:http://secunia.com/advisories/40096
受影响实体
- Ibm Websphere_application_server:7.0.0.7<!--2000-1-1-->
- Ibm Websphere_application_server:7.0.0.8<!--2000-1-1-->
- Ibm Websphere_application_server:7.0.0.6<!--2000-1-1-->
- Ibm Websphere_application_server:7.0.0.2<!--2000-1-1-->
- Ibm Websphere_application_server:7.0<!--2000-1-1-->
补丁
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Windows<!--2010-6-18-->
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for ibm i<!--2010-6-18-->
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for AIX<!--2010-6-18-->
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for AIX<!--2010-6-18-->
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for AIX<!--2010-6-18-->
还没有评论,来说两句吧...