CVE-2009-1898 Information
Feb 14, 2021
cve
Description
The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.
Reference
http://secunia.com/advisories/35301 http://www.securityfocus.com/bid/35405 http://www.vupen.com/english/advisories/2009/1464 http://www-01.ibm.com/support/docview.wss?uid=swg27006876 http://www-1.ibm.com/support/docview.wss?uid=swg1PK77010 https://exchange.xforce.ibmcloud.com/vulnerabilities/51170
Share on: