The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.
Link | Tags |
---|---|
http://www-1.ibm.com/support/docview.wss?uid=swg21261071 | |
http://www.securityfocus.com/bid/24608 | vdb entry patch |
http://secunia.com/advisories/25817 | third party advisory patch vendor advisory |
http://osvdb.org/41644 | vdb entry |
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24015854 | patch vendor advisory |
http://www.securitytracker.com/id?1018288 | vdb entry |