Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere应用服务器关闭连接信息泄露漏洞
Vulnerability Description
IBM Websphere应用服务器以Java和Servlet引擎为基础,支持多种HTTP服务,可帮助用户完成从开发、发布到维护交互式的动态网站的所有工作。 Websphere在处理连接的切断时存在漏洞,远程攻击者可能利用此漏洞获取某些内存中的敏感信息。 如果出现了关闭连接异常错误的话,例如在发送请求响应期间取消了请求,Web容器就可能破坏用于发送响应的缓冲区,导致将所取消请求的一些请求数据添加到之后请求的响应中,或将第一个之后请求的某些响应数据添加到不同请求的响应中,这样用户就可以在响应中获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A