CVE-2011-1310 Information

Description

The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 when tracing is enabled places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files which allows local users to obtain potentially sensitive information by reading these files.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg1PM18736 http://www-01.ibm.com/support/docview.wss?uid=swg27014463

Share on: