The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x prior to 6.1.0.35 and 7.x prior to 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm websphere application server 6.1.0.29 |
||
ibm websphere application server 6.1.0.27 |
||
ibm websphere application server 6.1.0.9 |
||
ibm websphere application server 6.1.0.1 |
||
ibm websphere application server 6.1.0.3 |
||
ibm websphere application server 6.1.0.19 |
||
ibm websphere application server 6.1.0.33 |
||
ibm websphere application server 6.1.0.17 |
||
ibm websphere application server 6.1.0.0 |
||
ibm websphere application server 6.1.0 |
||
ibm websphere application server 6.1.0.15 |
||
ibm websphere application server 6.1.0.7 |
||
ibm websphere application server 6.1.0.11 |
||
ibm websphere application server 6.1.0.12 |
||
ibm websphere application server 6.1.0.21 |
||
ibm websphere application server 6.1.0.23 |
||
ibm websphere application server 6.1.0.25 |
||
ibm websphere application server 6.1.0.31 |
||
ibm websphere application server 6.1.0.2 |
||
ibm websphere application server 6.1.0.5 |
||
ibm websphere application server 7.0.0.2 |
||
ibm websphere application server 7.0.0.6 |
||
ibm websphere application server 7.0.0.13 |
||
ibm websphere application server 7.0.0.5 |
||
ibm websphere application server 7.0.0.8 |
||
ibm websphere application server 7.0.0.7 |
||
ibm websphere application server 7.0.0.11 |
||
ibm websphere application server 7.0.0.4 |
||
ibm websphere application server 7.0.0.3 |
||
ibm websphere application server 7.0.0.9 |
||
ibm websphere application server 7.0 |
||
ibm websphere application server 7.0.0.1 |