Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere应用服务器本地信息泄露漏洞
Vulnerability Description
IBM Websphere应用服务器以Java和Servlet引擎为基础,支持多种HTTP服务,可帮助用户完成从开发、发布到维护交互式的动态网站的所有工作。 IBM WebSphere Application Server (WAS) 6.1.0.27之前的6.1版本和7.0.0.7之前的7.0版本在使用wsadmin脚本和JAAS-J2C认证数据的配置后不能正确处理某些异常。本地用户可通过读取WebSphere应用服务器的首次故障数据捕获(FFDC)日志文件获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A