CVE-2006-4137

IBM WebSphere Application Server <6.1.0.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.

References (7)

Core 7
Core References
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK28408&apar=only
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3262
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK27547&apar=only
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK27857&apar=only
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19463
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21440

Scores

EPSS 0.0133
EPSS Percentile 68.1%

Details

Status published
Products (16)
ibm/websphere_application_server 6.0
ibm/websphere_application_server 6.0.0.1
ibm/websphere_application_server 6.0.0.2
ibm/websphere_application_server 6.0.0.3
ibm/websphere_application_server 6.0.1
ibm/websphere_application_server 6.0.1.2
ibm/websphere_application_server 6.0.2
ibm/websphere_application_server 6.0.2.1
ibm/websphere_application_server 6.0.2.2
ibm/websphere_application_server 6.0.2.3
... and 6 more
Published Aug 14, 2006
Tracked Since Feb 18, 2026