Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, which allows remote attackers to obtain potentially sensitive status information via a direct request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WAS敏感信息泄露漏洞
Vulnerability Description
IBM WebSphere Application Server(WAS)是美国IBM公司开发并发行的一款应用服务器产品,它是Java EE和Web服务应用程序的平台,也是IBM WebSphere软件平台的基础。 IBM WebSphere Application Server(WAS)6.1.0.35之前的6.1版本以及7.0.1.15之前的7.0版本中的管理控制台组件没有正确限制对控制台servlet的访问。远程攻击者可以借助直接请求获得潜在敏感状态信息。
CVSS Information
N/A
Vulnerability Type
N/A