Description
The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-1893 | The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:27:54.775Z
Reserved: 2009-06-03T00:00:00.000Z
Link: CVE-2009-1898
No data.
Status : Modified
Published: 2009-06-03T17:00:00.610
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-1898
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD