CVE-2009-0437: Infoleak
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the WAS installation log file logs/instconfigifwas6.log by setting NTFS permissions so that only Administrators and the Local System account can read the file (remove read access for non-privileged local users).
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0437?
CVE-2009-0437 is considered to have a moderate severity level due to the exposure of sensitive information.
How do I fix CVE-2009-0437?
To mitigate CVE-2009-0437, ensure that log files are adequately secured and restrict access to sensitive logs.
What type of vulnerability is CVE-2009-0437?
CVE-2009-0437 is a local information disclosure vulnerability.
Who is affected by CVE-2009-0437?
CVE-2009-0437 affects IBM WebSphere Application Server version 6.0.2 running on Windows.
What can an attacker do with CVE-2009-0437?
An attacker with local access may read sensitive information from the logs of CVE-2009-0437.