CVE-2008-0740

IBM WebSphere Application Server < 6.0.2.24 - Sensitive Information Exposure in http_plugin.log

Title source: llm
STIX 2.1

Description

IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg27007951
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK48785
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/42878
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27400
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0241

Scores

EPSS 0.0033
EPSS Percentile 25.3%

Details

CWE
CWE-264
Status published
Products (1)
ibm/websphere_application_server < 6.0.2.24
Published Feb 13, 2008
Tracked Since Feb 18, 2026