CVE-2006-4137: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
Published Aug 14, 2006
·Updated
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
Affected Software
16 affected components
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.1
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.5
IBM WebSphere Application Server Feature Pack for Web Services=6.0.0.3
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.9
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.6
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.2
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.4
IBM WebSphere Application Server Feature Pack for Web Services=6.0.1.2
IBM WebSphere Application Server Feature Pack for Web Services=6.0.0.1
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.0
IBM WebSphere Application Server Feature Pack for Web Services=6.0.1
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.7
IBM WebSphere Application Server Feature Pack for Web Services=6.0.0.2
IBM WebSphere Application Server Feature Pack for Web Services=6.0
IBM WebSphere Application Server Feature Pack for Web Services=6.0.2.3
Remediation
Patch Available
Patch Available
Event History
Aug 14, 2006
CVE Published
11:04 PM
Aug 15, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4137?
CVE-2006-4137 is classified as a medium severity vulnerability.
2
What versions of IBM WebSphere Application Server are affected by CVE-2006-4137?
CVE-2006-4137 affects IBM WebSphere Application Server versions 6.0 and 6.1.0.0 and earlier.
3
How do I fix CVE-2006-4137?
To fix CVE-2006-4137, upgrade to IBM WebSphere Application Server version 6.1.0.1 or later.
4
What type of information can attackers obtain due to CVE-2006-4137?
Attackers may obtain sensitive information through the log file and traces due to CVE-2006-4137.
5
Is there a workaround for CVE-2006-4137?
There are no documented workarounds for CVE-2006-4137, so updating the software is recommended.