CVE-2009-1898 Information

Description

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.

Reference

http://secunia.com/advisories/35301 http://www.securityfocus.com/bid/35405 http://www.vupen.com/english/advisories/2009/1464 http://www-01.ibm.com/support/docview.wss?uid=swg27006876 http://www-1.ibm.com/support/docview.wss?uid=swg1PK77010 https://exchange.xforce.ibmcloud.com/vulnerabilities/51170

Share on: