Information disclosure in WebSphere Portal - CVE-2011-0679
Published: January 28, 2011 / Updated: August 11, 2020
WebSphere Portal
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."
How to mitigate CVE-2011-0679
Sources
- http://osvdb.org/70688
- http://secunia.com/advisories/43081
- http://www.ibm.com/support/docview.wss?uid=swg21460422
- http://www.kb.cert.org/vuls/id/375127
- http://www.securityfocus.com/bid/45989
- http://www.vupen.com/english/advisories/2011/0223
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM22159
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM22167
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM24319
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM24320
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM25191
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM25698
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM26397
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64890