Secunia Logo
 
CVE Reference: CVE-2006-2436
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-2436

Description:
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.

CVE Status:
Candidate

References:

SREASON
  http://securityreason.com/securityalert/910

SAID
  Secunia Advisory: SA20032

CONFIRM
  http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27006881

BUGTRAQ
  http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html

AIXAPAR
  http://www-1.ibm.com/support/search.wss?rs=0&q=PK17589&apar=only


Return to the previous page.