加入收藏 | 设为首页 | 会员中心 | 我要投稿 聊城站长网 (https://www.0635zz.com/)- 智能语音交互、行业智能、AI应用、云计算、5G!
当前位置: 首页 > 教程 > 正文

IBM WebSphere代码漏洞处理举措

发布时间:2023-07-05 14:38:31 所属栏目:教程 来源:
导读:WebSphere是IBM的软件平台,今天小编给大家分享一篇IBM WebSphere代码漏洞处理措施,感兴趣的朋友跟小编一起来了解一下吧!

  bugtraq id 1500

  class Access Validation Error

  cve GENERIC-MAP
WebSphere是IBM的软件平台,今天小编给大家分享一篇IBM WebSphere代码漏洞处理措施,感兴趣的朋友跟小编一起来了解一下吧!
 
  bugtraq id 1500
 
  class Access Validation Error
 
  cve GENERIC-MAP-NOMATCH
 
  remote Yes
 
  local Yes
 
  published July 24, 2000
 
  updated July 24, 2000
 
  vulnerable IBM Websphere Application Server 3.0.21
 
  - Sun Solaris 8.0
 
  - Microsoft Windows NT 4.0
 
  - Linux kernel 2.3.x
 
  - IBM AIX 4.3
 
  IBM Websphere Application Server 3.0
 
  - Sun Solaris 8.0
 
  - Novell Netware 5.0
 
  - Microsoft Windows NT 4.0
 
  - Linux kernel 2.3.x
 
  - IBM AIX 4.3
 
  IBM Websphere Application Server 2.0
 
  - Sun Solaris 8.0
 
  - Novell Netware 5.0
 
  - Microsoft Windows NT 4.0
 
  - Linux kernel 2.3.x
 
  - IBM AIX 4.3
 
  Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.
 
  This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.
 
  The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:
 
  "It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being
 
  parsed or compiled. For example if the URL for a file "login.jsp" is:
 
  http://site.running.websphere/login.jsp
 
  then accessing
 
  http://site.running.websphere/servlet/file/login.jsp
 
  would cause the unparsed contents of the file to show up in the web browser."
 
 

(编辑:聊城站长网)

【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容!