CVE-2005-3498
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 11.24% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/websphere application server
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1015134Third Party Advisory, VDB Entry
- http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27004980Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24010781Vendor Advisory
- http://www.securityfocus.com/bid/15303Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2005/2291Permissions Required, Third Party Advisory
- http://securitytracker.com/id?1015134Third Party Advisory, VDB Entry
- http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27004980Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24010781Vendor Advisory
- http://www.securityfocus.com/bid/15303Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2005/2291Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.