Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

IBM WebSphere Application Server 6.1 < Fix Pack 21 Multiple Vulnerabilities

Medium

Synopsis

The remote host is vulnerable to multiple attack vectors.

Description

IBM WebSphere Application Server 6.1 before Fix Pack 21 appears to be running on the remote host. Such versions are reportedly affected by multiple flaws :

- Provided Performance Monitoring Infrastructure (PMI) is enabled. It may be possible for a local attacker to obtain sensitive information through 'Systemout.log' and 'ffdc' files which are written by PerfServlet. - SSL Configuration settings attribute 'Security Level' does not correctly enforce the level of encryption used by the application server. (PK63182)

Solution

Apply Fix Pack 21 (6.1.0.21) or higher.