The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1PM22860 | vendor advisory |
http://www.securityfocus.com/bid/46736 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg27014463 | |
http://www.vupen.com/english/advisories/2011/0564 | vdb entry vendor advisory |