CVE-2006-4137
IBM WebSphere Application Server <6.1.0.1 - Info Disclosure
Title source: llmDescription
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
References (7)
Core 7
Core References
Patch vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK28408&apar=only
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3262
Patch vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK27547&apar=only
Patch vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK27857&apar=only
Patch x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27007951
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/19463
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21440
Scores
EPSS
0.0133
EPSS Percentile
68.1%
Details
Status
published
Products (16)
ibm/websphere_application_server
6.0
ibm/websphere_application_server
6.0.0.1
ibm/websphere_application_server
6.0.0.2
ibm/websphere_application_server
6.0.0.3
ibm/websphere_application_server
6.0.1
ibm/websphere_application_server
6.0.1.2
ibm/websphere_application_server
6.0.2
ibm/websphere_application_server
6.0.2.1
ibm/websphere_application_server
6.0.2.2
ibm/websphere_application_server
6.0.2.3
... and 6 more
Published
Aug 14, 2006
Tracked Since
Feb 18, 2026