CVE Reference: CVE-2010-0777

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-0777

Description:
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/58557

SAID
  Secunia Advisory: SA39838

CONFIRM
  http://www-01.ibm.com/support/docview.wss?uid=swg27007951

BID
  40277

AIXAPAR
  http://www-01.ibm.com/support/docview.wss?uid=swg1PM06111


Return to the previous page.