LOW
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log
Published Apr 30, 2010
1.9
LOWCVSS 2.0
EPSS 0.33%
Description
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.
Affected products
No data.
Configuration 1
AND
OR
- 6.1
- 6.1.0
- 6.1.0.0
- 6.1.0.1
- 6.1.0.2
- 6.1.0.3
- 6.1.0.4
- 6.1.0.5
- 6.1.0.6
- 6.1.0.7
- 6.1.0.8
- 6.1.0.9
- 6.1.0.10
- 6.1.0.11
- 6.1.0.12
- 6.1.0.13
- 6.1.0.14
- 6.1.0.15
- 6.1.0.16
- 6.1.0.17
- 6.1.0.18
- 6.1.0.19
- 6.1.0.20
- 6.1.0.21
- 6.1.0.22
- 6.1.0.23
- 6.1.0.24
- 6.1.0.25
- 6.1.0.26
- 6.1.0.27
- 6.1.0.29
- 6.1.1
- 6.1.3
- 6.1.5
- 6.1.6
- 6.1.7
- 6.1.13
- 6.1.14
Configuration 2
AND
OR
- 7.0
- 7.0.0.1
- 7.0.0.3
- 7.0.0.5
- 7.0.0.7
- 7.0.0.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://secunia.com/advisories/39628 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/40096 third-party-advisoryx_refsource_SECUNIA
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM08892 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247 vendor-advisoryx_refsource_AIXAPARPatch
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829 vendor-advisoryx_refsource_AIXAPAR
- http://www.osvdb.org/65437 vdb-entryx_refsource_OSVDB
- http://www.vupen.com/english/advisories/2010/1411 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58324 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/39628 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/40096 | third-party-advisoryx_refsource_SECUNIA | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1PM08892 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247 | vendor-advisoryx_refsource_AIXAPARPatch | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www.osvdb.org/65437 | vdb-entryx_refsource_OSVDB | |
| http://www.vupen.com/english/advisories/2010/1411 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/58324 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2010
Updated Aug 7, 2024
Reserved Apr 30, 2010
Link CVE-2010-1651
CISA Vulnrichment
Updated n/a