The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://securitytracker.com/id?1023551 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21417839 | patch vendor advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg1PM00610 | vendor advisory |
http://www.securityfocus.com/bid/38122 | vdb entry |
http://secunia.com/advisories/38425 | third party advisory vendor advisory |
http://www.osvdb.org/62140 | vdb entry |