CVE-2009-3106

IBM WebSphere Application Server 6.0.2 - Unauthenticated Information Disclosure via HTTP HEAD Request

Title source: llm
STIX 2.1

Description

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27006876
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53051
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK83258

Scores

EPSS 0.0278
EPSS Percentile 84.9%

Details

CWE
CWE-264
Status published
Products (34)
ibm/websphere_application_server 6.0.2 (2 CPE variants)
ibm/websphere_application_server 6.0.2.1
ibm/websphere_application_server 6.0.2.2
ibm/websphere_application_server 6.0.2.3
ibm/websphere_application_server 6.0.2.4
ibm/websphere_application_server 6.0.2.5
ibm/websphere_application_server 6.0.2.6
ibm/websphere_application_server 6.0.2.7
ibm/websphere_application_server 6.0.2.8
ibm/websphere_application_server 6.0.2.9
... and 24 more
Published Sep 08, 2009
Tracked Since Feb 18, 2026