1.9
CVSSv2

CVE-2011-1310

Published: 08/03/2011 Updated: 07/04/2011
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x prior to 6.1.0.35 and 7.x prior to 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server 6.1.0.29

ibm websphere application server 6.1.0.27

ibm websphere application server 6.1.0.9

ibm websphere application server 6.1.0.1

ibm websphere application server 6.1.0.3

ibm websphere application server 6.1.0.19

ibm websphere application server 6.1.0.33

ibm websphere application server 6.1.0.17

ibm websphere application server 6.1.0.0

ibm websphere application server 6.1.0

ibm websphere application server 6.1.0.15

ibm websphere application server 6.1.0.7

ibm websphere application server 6.1.0.11

ibm websphere application server 6.1.0.12

ibm websphere application server 6.1.0.21

ibm websphere application server 6.1.0.23

ibm websphere application server 6.1.0.25

ibm websphere application server 6.1.0.31

ibm websphere application server 6.1.0.2

ibm websphere application server 6.1.0.5

ibm websphere application server 7.0.0.2

ibm websphere application server 7.0.0.6

ibm websphere application server 7.0.0.13

ibm websphere application server 7.0.0.5

ibm websphere application server 7.0.0.8

ibm websphere application server 7.0.0.7

ibm websphere application server 7.0.0.11

ibm websphere application server 7.0.0.4

ibm websphere application server 7.0.0.3

ibm websphere application server 7.0.0.9

ibm websphere application server 7.0

ibm websphere application server 7.0.0.1