First published: Fri Apr 30 2010(Updated: )
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | =6.1 | |
Ibm Websphere Application Server | =6.1.0 | |
Ibm Websphere Application Server | =6.1.0.0 | |
Ibm Websphere Application Server | =6.1.0.1 | |
Ibm Websphere Application Server | =6.1.0.2 | |
Ibm Websphere Application Server | =6.1.0.3 | |
Ibm Websphere Application Server | =6.1.0.4 | |
Ibm Websphere Application Server | =6.1.0.5 | |
Ibm Websphere Application Server | =6.1.0.6 | |
Ibm Websphere Application Server | =6.1.0.7 | |
Ibm Websphere Application Server | =6.1.0.8 | |
Ibm Websphere Application Server | =6.1.0.9 | |
Ibm Websphere Application Server | =6.1.0.10 | |
Ibm Websphere Application Server | =6.1.0.11 | |
Ibm Websphere Application Server | =6.1.0.12 | |
Ibm Websphere Application Server | =6.1.0.13 | |
Ibm Websphere Application Server | =6.1.0.14 | |
Ibm Websphere Application Server | =6.1.0.15 | |
Ibm Websphere Application Server | =6.1.0.16 | |
Ibm Websphere Application Server | =6.1.0.17 | |
Ibm Websphere Application Server | =6.1.0.18 | |
Ibm Websphere Application Server | =6.1.0.19 | |
Ibm Websphere Application Server | =6.1.0.20 | |
Ibm Websphere Application Server | =6.1.0.21 | |
Ibm Websphere Application Server | =6.1.0.22 | |
Ibm Websphere Application Server | =6.1.0.23 | |
Ibm Websphere Application Server | =6.1.0.24 | |
Ibm Websphere Application Server | =6.1.0.25 | |
Ibm Websphere Application Server | =6.1.0.26 | |
Ibm Websphere Application Server | =6.1.0.27 | |
Ibm Websphere Application Server | =6.1.0.29 | |
Ibm Websphere Application Server | =6.1.1 | |
Ibm Websphere Application Server | =6.1.3 | |
Ibm Websphere Application Server | =6.1.5 | |
Ibm Websphere Application Server | =6.1.6 | |
Ibm Websphere Application Server | =6.1.7 | |
Ibm Websphere Application Server | =6.1.13 | |
Ibm Websphere Application Server | =6.1.14 | |
IBM z\/os | ||
Ibm Websphere Application Server | =7.0 | |
Ibm Websphere Application Server | =7.0.0.1 | |
Ibm Websphere Application Server | =7.0.0.3 | |
Ibm Websphere Application Server | =7.0.0.5 | |
Ibm Websphere Application Server | =7.0.0.7 | |
Ibm Websphere Application Server | =7.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1651 has a moderate severity rating due to exposure of sensitive information through insecure logging of SIP messages.
To fix CVE-2010-1651, upgrade IBM WebSphere Application Server to version 6.1.0.31 or 7.0.0.11 or later.
CVE-2010-1651 affects IBM WebSphere Application Server versions 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11.
CVE-2010-1651 allows local users to obtain sensitive information from the content of inbound and outbound SIP messages.
CVE-2010-1651 is not a remote vulnerability, as it requires local access to the system to exploit.