IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
Link | Tags |
---|---|
http://www-1.ibm.com/support/search.wss?rs=0&q=PK16492&apar=only | patch vendor advisory |
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064 | patch |
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012009 | patch |
http://www-1.ibm.com/support/docview.wss?rs=0&dc=DB550&q1=PK16492&uid=swg1PK22416&loc=en_US&cs=utf-8&lang= | patch vendor advisory |
http://securityreason.com/securityalert/910 | third party advisory |
http://www.vupen.com/english/advisories/2006/1736 | vdb entry |
http://secunia.com/advisories/20032 | third party advisory patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html | mailing list patch |
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24011773 | patch |
http://www.osvdb.org/25372 | vdb entry |