| Title | IBM WebSphere Application Server の Web コンテナにおける重要な情報を取得される脆弱性 |
|---|---|
| Summary | IBM WebSphere Application Server の Web コンテナには、長大なファイル名に対して適切な処理を行わず、レスポンスに対し誤ったファイルを送信するため、重要な情報を取得される脆弱性が存在します。 |
| Possible impacts | 第三者により、重要な情報を取得される可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | May 8, 2010, midnight |
| Registration Date | June 8, 2010, 6:24 p.m. |
| Last Update | Oct. 8, 2010, 5:05 p.m. |
| CVSS2.0 : 注意 | |
| Score | 2.6 |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
| IBM |
| IBM WebSphere Application Server 6.0.2.43 未満 |
| IBM WebSphere Application Server 6.1.0.31 未満 |
| IBM WebSphere Application Server 7.0.0.11 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2010年06月08日] 掲載 [2010年07月12日] ベンダ情報:IBM (7014463) を追加 [2010年10月08日] ベンダ情報:IBM (7006876) を追加 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file. |
|---|---|
| Publication Date | May 18, 2010, 7:30 a.m. |
| Registration Date | Jan. 29, 2021, 10:57 a.m. |
| Last Update | Aug. 17, 2017, 10:32 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:ibm:websphere_application_server:6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.13:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.1.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.12:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.13:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.14:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.16:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.18:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.19:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.20:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.21:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.22:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.23:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.24:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.25:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.27:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.28:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.29:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.30:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.31:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.32:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.33:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.35:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.37:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.0.2.39:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.13:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.19:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.21:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.23:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.25:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.27:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:6.1.0.29:*:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:* | |||||