PT-2013-2453 · Ibm · Ibm Eclipse Help System

Publicado

2013-05-28

·

Atualizado

2017-08-29

·

CVE-2013-0599

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Eclipse Help System (IEHS) versions 5.1.1 through 5.1.1.2 IBM Eclipse Help System (IEHS) versions 5.2 through 5.2.1
Description The issue allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.
Recommendations For versions 5.1.1 through 5.1.1.2, consider restricting access to debug information to minimize the risk of exploitation. For versions 5.2 through 5.2.1, avoid using crafted parameter paths in API endpoints until the issue is resolved. As a temporary workaround, consider disabling debug information for the 500 HTTP status code until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0599

Produtos afetados

Ibm Eclipse Help System