CVE-2010-2326: Infoleak
Published Jun 18, 2010
·Updated
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file.
Affected Software
6 affected components
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.5
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.9
IBM WebSphere Application Server Feature Pack for Web Services=7.0
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.7
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.3
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.1
Event History
Jun 18, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2326?
CVE-2010-2326 is classified as a medium severity vulnerability.
2
How do I fix CVE-2010-2326?
To resolve CVE-2010-2326, upgrade IBM WebSphere Application Server to version 7.0.0.11 or later.
3
What type of information can be exposed by CVE-2010-2326?
CVE-2010-2326 allows attackers to obtain sensitive information regarding CIMMetadataCollectorImpl trace actions from the addNode.log file.
4
Which versions of IBM WebSphere Application Server are affected by CVE-2010-2326?
CVE-2010-2326 impacts versions 7.0.0.1 through 7.0.0.9 of IBM WebSphere Application Server.
5
Is there a workaround for CVE-2010-2326 if immediate upgrade is not possible?
There is no documented workaround for CVE-2010-2326, so upgrading is the recommended action.