![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2010-1651 |
Description: | IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-1651 AIX APAR: PM08892 http://www-01.ibm.com/support/docview.wss?uid=swg1PM08892 AIX APAR: PM12247 http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247 AIX APAR: PM15829 http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829 http://www.osvdb.org/65437 http://secunia.com/advisories/39628 http://secunia.com/advisories/40096 http://www.vupen.com/english/advisories/2010/1411 XForce ISS Database: ibm-was-trace-information-disclosure(58324) https://exchange.xforce.ibmcloud.com/vulnerabilities/58324 |