CVE-2016-2961: Infoleak
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2961?
CVE-2016-2961 is rated as a medium severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2016-2961?
To fix CVE-2016-2961, update your IBM Integration Bus to version 9.0.0.6 or higher, and WebSphere Message Broker to version 8.0.0.8 or higher.
What systems are affected by CVE-2016-2961?
CVE-2016-2961 affects IBM Integration Bus versions 9.0 before 9.0.0.6 and 10 before 10.0.0.5, as well as WebSphere Message Broker versions 8 before 8.0.0.8.
What type of attack does CVE-2016-2961 involve?
CVE-2016-2961 involves a remote attack that can result in the exposure of sensitive Tomcat version information.
Can CVE-2016-2961 be exploited remotely?
Yes, CVE-2016-2961 can be exploited remotely through a specially crafted POST request.