CVE-2012-2170

IBM WebSphere Application Server 7.0 - Unauthenticated Sensitive Information Exposure via Application Snoop Servlet

Title source: llm
STIX 2.1

Description

The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client and request information via a direct request.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75234
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1PM56183
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21595172

Scores

EPSS 0.0239
EPSS Percentile 82.2%

Details

CWE
CWE-264
Status published
Products (16)
ibm/websphere_application_server 7.0
ibm/websphere_application_server 7.0.0.1
ibm/websphere_application_server 7.0.0.2
ibm/websphere_application_server 7.0.0.3
ibm/websphere_application_server 7.0.0.4
ibm/websphere_application_server 7.0.0.5
ibm/websphere_application_server 7.0.0.6
ibm/websphere_application_server 7.0.0.7
ibm/websphere_application_server 7.0.0.8
ibm/websphere_application_server 7.0.0.9
... and 6 more
Published Jun 20, 2012
Tracked Since Feb 18, 2026