cbcvebase.
CVE-2005-3498
published 2005-11-04

CVE-2005-3498: IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL…

medium4.3CVSS 3.1
AVNACMAuNCPINAN
EXPLOIT
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.

Affected

3 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server>= 5.0.0 < 5.02.155.02.15
ibmwebsphere_application_server>= 5.1.0 < 5.1.1.85.1.1.8
ibmwebsphere_application_server>= 6.0.0 < 6.0.2.56.0.2.5