Release date:
Updated on:
Affected Systems:
IBM WebSphere Sensor Events 7.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53859
IBM WebSphere Sensor Events provides a middleware infrastructure for creating and managing enterprise-level sensors.
The implementation of IBM WebSphere Sensor Events includes P001414 XSS, file path traversal, insecure HTTP method, and searchView. deferredView in jsp. cross-Site Scripting Vulnerability P001538 in jsp XSS. Attackers can exploit this vulnerability to steal Cookie authentication creden。, perform illegal operations, or leak sensitive information.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: http://www-304.ibm.com/support/docview.wss? Uid = swg24032733
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
For this reason, IBM has released a Security Bulletin (4032733) and corresponding patches:
4032733: WebSphere Sensor Events interim fixes-IC83621 and IC83623
Link: http://www-304.ibm.com/support/docview.wss? Uid = swg24032733