CVE-2010-0563: Infoleak
The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0563?
CVE-2010-0563 is considered to have a high severity due to the potential exposure of sensitive information through unencrypted network sessions.
How do I fix CVE-2010-0563?
To fix CVE-2010-0563, ensure that SSL is properly configured and enforced on the IBM WebSphere Application Server.
What versions of IBM WebSphere Application Server are affected by CVE-2010-0563?
CVE-2010-0563 affects versions 7.0.0.1 through 7.0.0.8 of IBM WebSphere Application Server.
What vulnerability does CVE-2010-0563 exploit?
CVE-2010-0563 exploits the lack of recognition of the Requires SSL configuration in the SSO functionality of IBM WebSphere Application Server.
What are the potential consequences of CVE-2010-0563?
The potential consequences of CVE-2010-0563 include remote attackers being able to sniff and capture sensitive information transmitted over the network.