CVE-2016-2961
02.07.2016, 14:59
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | integration_bus | 9.0 |
ibm | integration_bus | 9.0.0.1 |
ibm | integration_bus | 9.0.0.2 |
ibm | integration_bus | 9.0.0.3 |
ibm | integration_bus | 9.0.0.4 |
ibm | integration_bus | 9.0.0.5 |
ibm | integration_bus | 10.0 |
ibm | integration_bus | 10.0.0.1 |
ibm | integration_bus | 10.0.0.2 |
ibm | integration_bus | 10.0.0.3 |
ibm | integration_bus | 10.0.0.4 |
ibm | websphere_message_broker | 8.0 |
ibm | websphere_message_broker | 8.0.0.1 |
ibm | websphere_message_broker | 8.0.0.2 |
ibm | websphere_message_broker | 8.0.0.3 |
ibm | websphere_message_broker | 8.0.0.4 |
ibm | websphere_message_broker | 8.0.0.5 |
ibm | websphere_message_broker | 8.0.0.6 |
ibm | websphere_message_broker | 8.0.0.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration