CVE-2006-4137Sensitive Information Exposure in IBM Websphere Application Server

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 34.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 1

Description

IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

4
GHSA
GHSA-f8qh-r27m-q974: IBM WebSphere Application Server (WAS) before 62022-05-01
GHSA
GHSA-ph4m-3cp9-772w: IBM WebSphere Application Server before 62022-05-01
CVEList
CVE-2006-4223: IBM WebSphere Application Server (WAS) before 62006-08-18
CVEList
CVE-2006-4137: IBM WebSphere Application Server before 62006-08-14
CVE-2006-4137 — Sensitive Information Exposure in IBM | cvebase