Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere Application Server QueryString信息泄露漏洞
Vulnerability Description
IBM WebSphere Application Server(WAS)是 IBM WebSphere 软件平台的基础和面向服务的体系结构的关键构件。 IBM WebSphere Application Server 5.0.x中5.02.15之前的版本、5.1.x中5.1.1.8之前的版本以及6.x中V6.0.2.5修订包之前的版本,在启用会话跟踪时,如果应用程序对URL进行了编码,便会记录包含跟踪日志中queryString的完整URL,这可让攻击者获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A