IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2010/1411 | vdb entry vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM10684 | vendor advisory |
http://www.osvdb.org/65438 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830 | vendor advisory |
http://secunia.com/advisories/40096 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/40699 | vdb entry |