| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.100565 |
| Category: | Web application abuses |
| Title: | IBM WebSphere Application Server multiple vulnerabilities |
| Summary: | Determine if installed WebSphere Application Server version is vulnerable. |
| Description: | Overview: IBM WebSphere Application Server (WAS) is prone to multiple vulnerabilities. 1. A cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. 2. A Remote Denial Of Service Vulnerability. Exploiting this issue allows remote attackers to cause WAS ORB threads to hang, denying service to legitimate users. Versions prior to WAS 7.0.0.9, 6.1.0.31, and 6.0.2.4 are vulnerable. Solution: The vendor has released updates. Please see the references for details. References: http://www.securityfocus.com/bid/39051 http://www.securityfocus.com/bid/39056 http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg27004980 http://www-306.ibm.com/software/websphere/# http://xforce.iss.net/xforce/xfdb/57164 http://xforce.iss.net/xforce/xfdb/57182 |
| Cross-Ref: |
BugTraq ID: 39051 BugTraq ID: 39056 Common Vulnerability Exposure (CVE) ID: CVE-2010-0768 AIX APAR: PK97376 http://www-01.ibm.com/support/docview.wss?uid=swg1PK97376 http://www.securityfocus.com/bid/39051 http://secunia.com/advisories/39140 XForce ISS Database: was-admin-console-xss(57164) http://xforce.iss.net/xforce/xfdb/57164 Common Vulnerability Exposure (CVE) ID: CVE-2010-0770 AIX APAR: PK93653 http://www-01.ibm.com/support/docview.wss?uid=swg1PK93653 http://www.securityfocus.com/bid/39056 XForce ISS Database: was-orb-client-dos(57182) http://xforce.iss.net/xforce/xfdb/57182 Common Vulnerability Exposure (CVE) ID: CVE-2010-0769 AIX APAR: PK95089 http://www-01.ibm.com/support/docview.wss?uid=swg1PK95089 XForce ISS Database: was-wsadmin-info-disclosure(57185) http://xforce.iss.net/xforce/xfdb/57185 |
| Copyright | This script is Copyright (C) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|