IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2010/1411 | vdb entry vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830 | vendor advisory |
http://secunia.com/advisories/40096 | third party advisory vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM10454 | vendor advisory |