CVE-2007-3397

IBM WebSphere Application Server <6.0.2.21 & <6.1.0.9 - Info Disclo...

Title source: llm
STIX 2.1

Description

The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg21261071
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24608
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25817
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41644
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24015854
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018288

Scores

EPSS 0.0215
EPSS Percentile 80.2%

Details

Status published
Products (20)
ibm/websphere_application_server 6.0.2
ibm/websphere_application_server 6.0.2.1
ibm/websphere_application_server 6.0.2.2
ibm/websphere_application_server 6.0.2.3
ibm/websphere_application_server 6.0.2.4
ibm/websphere_application_server 6.0.2.5
ibm/websphere_application_server 6.0.2.6
ibm/websphere_application_server 6.0.2.7
ibm/websphere_application_server 6.0.2.9
ibm/websphere_application_server 6.0.2.11
... and 10 more
Published Jun 26, 2007
Tracked Since Feb 18, 2026