CVE-2007-3397IBM Websphere Application Server vulnerability

3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
0.7%
top 28.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 1

Description

The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rvqc-v6vj-m9pw: The web container in IBM WebSphere Application Server (WAS) before 62022-05-01
CVEList
CVE-2007-3397: The web container in IBM WebSphere Application Server (WAS) before 62007-06-26
CVE-2007-3397 — IBM vulnerability | cvebase