PT-2008-2021 · Ibm · Ibm Websphere Application Server

Published

2008-01-23

·

Updated

2017-08-08

·

CVE-2008-0389

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 5.1.1.x through 5.1.1.17 IBM WebSphere Application Server versions 6.0 through 6.0.2.25 IBM WebSphere Application Server versions 6.1 through 6.1.0.14
Description The issue concerns an unspecified vulnerability in the serveServletsByClassnameEnabled feature. Details about the impact and attack vectors of this issue are not provided.
Recommendations For IBM WebSphere Application Server versions 5.1.1.x through 5.1.1.17, update to version 5.1.1.18 or later. For IBM WebSphere Application Server versions 6.0 through 6.0.2.25, consider disabling the serveServletsByClassnameEnabled feature as a temporary workaround until a patch is available. For IBM WebSphere Application Server versions 6.1 through 6.1.0.14, restrict access to the affected feature to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-0389

Affected Products

Ibm Websphere Application Server