CVE-2008-0740
IBM WebSphere Application Server < 6.0.2.24 - Sensitive Information Exposure in http_plugin.log
Title source: llmDescription
IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.
References (6)
Core 6
Core References
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg27007951
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK48785
Patch x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg27006876
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/42878
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/27400
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0241
Scores
EPSS
0.0033
EPSS Percentile
25.3%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/websphere_application_server
< 6.0.2.24
Published
Feb 13, 2008
Tracked Since
Feb 18, 2026