CVE-2008-0740: Low severity ibm websphere application server feature pack for web services vulnerability
Published Feb 13, 2008
·Updated
IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to httpplugin.log, which might allow local users to obtain sensitive information by reading this file.
Affected Software
1 affected component
IBM WebSphere Application Server Feature Pack for Web Services<=6.0.2.24
Remediation
Patch Available
Event History
Feb 13, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0740?
The severity of CVE-2008-0740 is considered moderate due to potential exposure of sensitive information.
2
How do I fix CVE-2008-0740?
To fix CVE-2008-0740, upgrade IBM WebSphere Application Server to version 6.0.2.25 or 6.1.0.15 or later.
3
What does CVE-2008-0740 affect?
CVE-2008-0740 affects IBM WebSphere Application Server versions prior to 6.0.2.25 and 6.1.0.15.
4
What type of information is leaked by CVE-2008-0740?
CVE-2008-0740 may leak sensitive information in cleartext to the http_plugin.log file.
5
Who can exploit CVE-2008-0740?
Local users with access to the server can exploit CVE-2008-0740 to obtain sensitive information.