PT-2010-2320 · Ibm · Ibm Websphere Application Server

Publicado

2010-02-08

·

Atualizado

2010-11-03

·

CVE-2010-0563

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 7.0.0.0 through 7.0.0.8
Description The Single Sign-on (SSO) functionality in IBM WebSphere Application Server does not recognize the Requires SSL configuration option. This might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
Recommendations For versions 7.0.0.0 through 7.0.0.8, consider configuring the SSO functionality to use an alternative encryption method until a fix is available. As a temporary workaround, restrict access to sensitive information over unencrypted network sessions.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0563

Produtos afetados

Ibm Websphere Application Server