CVE-2009-3106
IBM WebSphere Application Server 6.0.2 - Unauthenticated Information Disclosure via HTTP HEAD Request
Title source: llmDescription
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.
References (3)
Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27006876
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53051
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK83258
Scores
EPSS
0.0278
EPSS Percentile
84.9%
Details
CWE
CWE-264
Status
published
Products (34)
ibm/websphere_application_server
6.0.2 (2 CPE variants)
ibm/websphere_application_server
6.0.2.1
ibm/websphere_application_server
6.0.2.2
ibm/websphere_application_server
6.0.2.3
ibm/websphere_application_server
6.0.2.4
ibm/websphere_application_server
6.0.2.5
ibm/websphere_application_server
6.0.2.6
ibm/websphere_application_server
6.0.2.7
ibm/websphere_application_server
6.0.2.8
ibm/websphere_application_server
6.0.2.9
... and 24 more
Published
Sep 08, 2009
Tracked Since
Feb 18, 2026